VendorsSRCMS Projectsrcmsall versions
Vulnerabilities

SRCMS Project SRCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-14068
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.
Published 2018-07-15 · Modified
8.8EPSS 0.007
CVE-2018-14069
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add.
Published 2018-07-15 · Modified
8.8EPSS 0.005
CVE-2018-19318
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
Published 2018-11-16 · Modified
8.8EPSS 0.005
CVE-2018-19319
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
Published 2018-11-16 · Modified
6.5EPSS 0.004