← Back to CVE List

CVE-2018-8972

Published: 2018-03-24T22:29Z
Last Modified: 2024-11-21T04:14Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt