CSRF esiste in zb_users / plugin / AppCentre / theme.js.php in Z-BlogPHP 1.5.2.1935 (zero), che consente agli aggressori remoti di eseguire codice PHP arbitrario. |
https://github.com/zblogcn/zblogphp/files/2524853/CSRF.Vulnerability.exists.in.the.file.of.Z-BLOG.1.5.2.1935.docx https://github.com/zblogcn/zblogphp/issues/201 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18842 |
Vulnerabilità: CVE-2018-18842
