CVE-2017-12838: Nexusphp Project Nexusphp

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.

Affected products

Published 2017-09-07. Last modified 2026-06-17.