HIGH
Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters
Published Mar 24, 2018
8.8
HIGHCVSS 3.0
EPSS 0.56%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.