CVE-2018-25334
Last modified
CVE-2018-25334 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypass the CSRF protection, allowing for unauthorized changes to user data. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypass the CSRF protection, allowing for unauthorized changes to user data. This can be exploited by tricking a user into submitting a crafted form or by using a script to obtain and set the CSRF token.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2018-25334?
How severe is CVE-2018-25334?
How do I fix CVE-2018-25334?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-25328VX Search 10.6.18 contains a local buffer overflow vulnerabi…8.6
- CVE-2018-25329WordPress Plugin WP with Spritz 1.0 contains a remote file i…8.7
- CVE-2018-25330Joomla! extension EkRishta 2.10 contains persistent cross-si…8.8
- CVE-2018-25331Zenar Content Management System contains a cross-site script…6.1
- CVE-2018-25332GitBucket 4.23.1 contains an unauthenticated remote code exe…9.8
- CVE-2018-25333Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an …8.8
- CVE-2018-25335WordPress Plugin Peugeot Music 1.0 contains an arbitrary fil…9.8
- CVE-2018-25336jCart for OpenCart 2.3.0.2 contains a cross-site request for…6.9
- CVE-2018-25337Joomla JoomOCShop 1.0 contains a cross-site request forgery …5.3
- CVE-2018-25338Zechat 1.5 contains a SQL injection vulnerability in the has…8.8
- CVE-2018-25339Zechat 1.5 contains a SQL injection vulnerability in the v p…8.8
- CVE-2018-25340Smartshop 1 contains a SQL injection vulnerability that allo…8.8
Are you affected by CVE-2018-25334?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
