PT-2026-23700 · Unknown · Easyndexer

CVE-2018-25190

·

Publicado

2026-03-06

·

Atualizado

2026-03-06

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Easyndexer version 1.0
Description The software contains a cross-site request forgery issue that permits unauthenticated attackers to create administrative accounts. This is achieved by submitting crafted POST requests. Attackers can create malicious web pages that submit POST requests to the ''createuser.php'' endpoint. The request includes parameters such as username, password, name, surname, and privileges. Setting privileges to 1 grants administrator access.
Recommendations Apply a fix to prevent the creation of administrative accounts via forged POST requests to the ''createuser.php'' endpoint.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-25190

Produtos afetados

Easyndexer