CVE-2019-10888

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
05/04/2019
Last modified:
07/04/2019

Description

A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ukcms:ukcms:1.1.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools