Back to Database
Status published
High
CVE-2018-18842
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows...
Vulnerability Description
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18842
Credits & Attribution
No credits recorded in the NVD database.
References
More from zblogcn
View All →CVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A...
Unknown
0
CVE-2020-29177
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion...
Critical
9.1
CVE-2020-29176
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers...
High
7.8
CVE-2020-23352
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP...
High
7.5
CVE-2020-23327
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows...
Medium
6.1
Affected Vendor
zblogcn
View all reports →Affected Software
z-blogphp
Vulnerable Versions:
1.5.2.1935\(zero\)
Timeline
Official Publish:
October 30th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.