OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to administrative privileges to gain unauthorized access.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/45794 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/oop-cms-blog-cross-site-request-forgery-via-adduserphp | Broken Link |
Configurations
History
11 Mar 2026, 00:35
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:tomalofficial:php_oop_cms_blog:1.0:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://www.exploit-db.com/exploits/45794 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/oop-cms-blog-cross-site-request-forgery-via-adduserphp - Broken Link | |
| First Time |
Tomalofficial
Tomalofficial php Oop Cms Blog |
06 Mar 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-06 13:16
Updated : 2026-03-11 00:35
NVD link : CVE-2018-25200
Mitre link : CVE-2018-25200
CVE.ORG link : CVE-2018-25200
JSON object : View
Products Affected
tomalofficial
- php_oop_cms_blog
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
