SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/martinzhou2015/SRCMS-dev/issues/1 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-11-16T19:00:00Z
Updated: 2024-09-16T17:14:38.139Z
Reserved: 2018-11-16T00:00:00Z
Link: CVE-2018-19319
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-11-16T19:29:00.367
Modified: 2024-11-21T03:57:42.843
Link: CVE-2018-19319
Redhat
No data.