Srcms Project / Srcms
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-19319 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges. | MEDIUM | 6.5 | Nov 16, 2018 |
| CVE-2018-19318 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account. | HIGH | 8.8 | Nov 16, 2018 |
| CVE-2018-14069 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add. | HIGH | 8.8 | Jul 15, 2018 |
| CVE-2018-14068 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add. | HIGH | 8.8 | Jul 15, 2018 |
Showing 1 to 4 of 4 CVEs