index.php? m = membro & v = pw_reset in Wuzhi CMS 4.1.0 permette CSRF per modificare la password di un membro comune. |
https://www.exploit-db.com/exploits/44504/ https://github.com/wuzhicms/wuzhicms/issues/132 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10312 |
Vulnerabilità: CVE-2018-10312
