Vulnerabilities > Onethink > Onethink > 1.1.141212

DATE CVE VULNERABILITY TITLE RISK
2018-09-04 CVE-2018-16449 Cross-Site Request Forgery (CSRF) vulnerability in Onethink 1.1.141212
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.
network
onethink CWE-352
4.3