CVE-2014-8429: Xavoc Xepan CMS
Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted request to the owner/users page.
Affected products
- Xavoc Xepan CMS: up to and including 1.0.1; version 1.0.4 only; version 1.0.4.1 only
Published 2014-11-28. Last modified 2026-06-17.