CVE-2018-12583
UnknownEPSS 0.48%
Last modified
CVE-2018-12583 is a vulnerability of currently unknown severity. An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Akcms Project | Akcms | 6.1 |
References
- https://github.com/chenrui1896/issue/blob/master/del_articleExploit, Third Party Advisory
- https://github.com/p8w/akcms/issues/2Exploit, Third Party Advisory
- https://github.com/chenrui1896/issue/blob/master/del_articleExploit, Third Party Advisory
- https://github.com/p8w/akcms/issues/2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12583?
An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
How severe is CVE-2018-12583?
Severity scoring for CVE-2018-12583 is pending analysis. The EPSS model estimates a 0.48% probability of exploitation in the next 30 days.
How do I fix CVE-2018-12583?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12578There is a heap-based buffer overflow in bmp_compress1_row i…
- CVE-2018-12579An issue was discovered in OXID eShop Enterprise Edition bef…
- CVE-2018-1258Spring Framework version 5.0.5 when used in combination with…8.8
- CVE-2018-12580library/DBTech/Security/Action/Sessions.php in DragonByte vB…
- CVE-2018-12581An issue was discovered in js/designer/move.js in phpMyAdmin…
- CVE-2018-12582An issue was discovered in AKCMS 6.1. CSRF can add an admin …
- CVE-2018-12584The ConnectionBase::preparseNewBytes function in resip/stack…9.8
- CVE-2018-12585An XXE vulnerability in the OPC UA Java and .NET Legacy Stac…
- CVE-2018-12587A cross-site scripting (XSS) vulnerability was found in vale…
- CVE-2018-12588Cross-site scripting (XSS) vulnerability in templates/fronte…
- CVE-2018-12589Polaris Office 2017 8.1 allows attackers to execute arbitrar…
- CVE-2018-1259Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 …7.5
Are you affected by CVE-2018-12583?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
