#VU14706 Cross-site request forgery in Frog CMS - CVE-2018-8908
Published: September 8, 2018 / Updated: June 17, 2021
Frog CMS
Frog CMS Project
Description
The vulnerability allows a remote attacker to perform CSRF attacks.
The vulnerability exists due to improper handling of the HTTP request origin in "/admin/?/user/add" URL. A remote attacker can trick the victim into visiting a specially specially crafted web page and create a user with administrative privileges.