RULE(RULE ID:330946)

Rule General Information
Release Date: 2020-08-26
Rule Name: MiniCMS 1.10 CSRF Vulnerability (CVE-2018-9092)
Severity:
CVE ID:
Rule Protection Details
Description: There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
Impact: An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:44362
https://github.com/bg5sbk/MiniCMS/issues/14
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://1234n.com/?projects/minicms/