CVE-2018-18794
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
- Affected products
- School Management System
- School Event Management System Project School Event Management System
- = 1.0
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2018-11-16
CVE-2018-18794 at NVD
4 known exploits for CVE-2018-18794
Proof-of-concept code and exploit modules indexed by Sploitus
School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin) Vulnerability
School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
School Event Management System 1.0 Cross Site Request Forgery