An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
References
| Link | Resource |
|---|---|
| https://gitee.com/mingSoft/MCMS/issues/IM1DA | Broken Link |
| https://gitee.com/mingSoft/MCMS/issues/IM1DA | Broken Link |
Configurations
History
19 Feb 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mingsoft:mcms:4.6.5:*:*:*:*:*:*:* | |
| First Time |
Mingsoft
Mingsoft mcms |
21 Nov 2024, 03:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitee.com/mingSoft/MCMS/issues/IM1DA - Broken Link |
Information
Published : 2018-09-23 18:29
Updated : 2026-02-19 18:39
NVD link : CVE-2018-17366
Mitre link : CVE-2018-17366
CVE.ORG link : CVE-2018-17366
JSON object : View
Products Affected
mingsoft
- mcms
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
