CVE-2014-8429: Xavoc Xepan CMS

Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted request to the owner/users page.

Affected products

  • Xavoc Xepan CMS: up to and including 1.0.1; version 1.0.4 only; version 1.0.4.1 only

Published 2014-11-28. Last modified 2026-06-17.