CVE-2018-16314

CVE-2018-16314

An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header.

Source: CVE-2018-16314

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다