RULE(RULE ID:330973)

Rule General Information
Release Date: 2020-08-26
Rule Name: WUZHI CMS 4.1.0 CSRF Vulnerability (CVE-2018-9927)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.
Impact: An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt.
Affected OS: Windows, Others
Reference: http://www.iwantacve.cn/index.php/archives/7/
https://github.com/wuzhicms/wuzhicms/issues/128
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.wuzhicms.com/