Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication. | |
| Title | Tina4 Stack 1.0.3 Cross-Site Request Forgery via profile | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-06T12:19:12.879Z
Reserved: 2026-03-06T11:56:44.324Z
Link: CVE-2018-25186
No data.
Status : Received
Published: 2026-03-06T13:16:01.020
Modified: 2026-03-06T13:16:01.020
Link: CVE-2018-25186
No data.
OpenCVE Enrichment
No data.