Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2018-18449

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
0
Attacker Value
Unknown

CVE-2018-16339

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
0