Description
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4463 | An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. |
Github GHSA |
GHSA-m246-pv28-4r6f | Mingsoft MCMS CSRF vulnerability |
References
| Link | Providers |
|---|---|
| https://gitee.com/mingSoft/MCMS/issues/IM1DA |
|
History
Thu, 19 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mingsoft
Mingsoft mcms |
|
| CPEs | cpe:2.3:a:mingsoft:mcms:4.6.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Mcms Project
Mcms Project mcms |
Mingsoft
Mingsoft mcms |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:47:04.301Z
Reserved: 2018-09-23T00:00:00.000Z
Link: CVE-2018-17366
No data.
Status : Modified
Published: 2018-09-23T18:29:00.907
Modified: 2026-02-19T18:39:55.267
Link: CVE-2018-17366
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA