CVE-2018-10224
https://notcve.org/view.php?id=CVE-2018-10224
19 Apr 2018 — An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html. Se ha descubierto un problema en YzmCMS 3.8. Hay una vulnerabilidad de Cross-Site Request Forgery (CSRF) que puede añadir una etiqueta mediante /index.php/admin/tag/add.html. • http://www.8sec.cc/archives/601 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-10223
https://notcve.org/view.php?id=CVE-2018-10223
19 Apr 2018 — An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html. Se ha descubierto un problema en YzmCMS 3.8. Hay una vulnerabilidad de Cross-Site Request Forgery (CSRF) que puede añadir una cuenta admin mediante /index.php/admin/admin_manage/add.html. • http://www.8sec.cc/archives/596 • CWE-352: Cross-Site Request Forgery (CSRF) •