phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
2018-06-30T14:29:00.240
2024-11-21T03:46:12.087
Modified
[email protected]
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9