PT-2026-44875 · Undefined · Undefined

CVE-2018-25397

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHP-SHOP version 1.0
Description A cross-site request forgery (CSRF) issue allows unauthenticated attackers to create unauthorized administrative accounts. This occurs when authenticated administrators are tricked into visiting a page with a hidden HTML form that automatically sends POST requests to the 'users.php' endpoint. The attack utilizes the name, email, password, and permissions variables, setting the latter to admin to grant full administrative privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25397

Affected Products

Undefined