CVE-2018-7308

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
21/02/2018
Last modified:
16/03/2018

Description

A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hosting_project:hosting:*:*:*:*:*:*:*:* 2018-02-11 (including)