We found results for “”
CVE-2018-15203
Good to know:
Date: August 7, 2018
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix
Upgrade Version
Upgrade to version bappa2du/codeit - no_fix;opensource-workshop/connect-cms - dev-PageManage;opensource-workshop/connect-cms - v0.0.1.20210104;opensource-workshop/connect-cms - v0.0.1.20201008;opensource-workshop/connect-cms - v0.0.1.20201207;opensource-workshop/connect-cms - v0.0.1.20220207;rogeriopradoj/codeigniter - dev-2.2-stable;rogeriopradoj/codeigniter - 2.2.1;rogeriopradoj/codeigniter - dev-upstream-develop;rogeriopradoj/codeigniter - no_fix;nielbuys/framework - 3.0.4;schachbulle/contao-forum-bundle - 0.0.4;schachbulle/contao-forum-bundle - no_fix;jhjjang/sns_login - no_fix;codeigniter31/framework - 3.0.4;kodazzi/amazonas - no_fix;kodazzi/amazonas - v1.0.0-alpha;codeigniter/framework - 3.0.4;codeigniter/framework - 2.2.1;ellislab/codeigniter - 3.0.4;ellislab/codeigniter - 2.2.1;agriya/webshoppack - no_fix;roulette/roulette - no_fix;iet-ou/open-media-player - 1.2;timexstudio/codeigniter-3-orm-twig - no_fix;chriskacerguis/codeigniter-restserver - 2.7.2;carlosocarvalho/xml-table-data-manager - no_fix;webwizo/codeigniter-eloquent - no_fix;rnkpatel/laravel-blog - no_fix;robjuz/cakephp-kovicky - no_fix;despark/ignicms - no_fix;fbc-sis/codeigniter - 3.0.4;acosf/archersys - 2.0.1;acosf/archersys - 2.0.0;pragmaticlinux/codeigniter - no_fix;webdmg/codeigniter - v0.1.0;marcelod/codeistrap - no_fix;mawoo/migrationeditor - no_fix;maxtream/themages - no_fix;tastyigniter/tastyigniter - v1.0.0;hanischit/codeigniter-restserver - 2.7.2;bcit-ci/codeigniter - 3.0.4;savy/admin - no_fix;savy/admin - 1.0.3;vtlfokin/codeigniter - 2.2.1;webdmg/system-c - v0.1.0;hjue/justwriting - v0.0.3;bappa2du/fast - no_fix;rebekz/codeigniter_basic - no_fix;livecms/core - no_fix;dark-prospect-games/facebook-ignited - v1.2.0;cappuccinodigital/cup-cms - no_fix;despark/igni-core - no_fix;livecms/livecms - dev-liveCommerce;ardissoebrata/ci-beam - v1.1;ezrun/framework-standard-edition - no_fix;renanmpimentel/codeigniter_start - no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


