CyberRota
Back to database

CVE-2018-25337

MEDIUM · CVSS 4.3 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-17 · Last synced: 2026-06-16

CyberRota Analysis

Saldırganın giriş yapmış olması gerekebilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-25337
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.