CVE-2017-12838: Nexusphp Project Nexusphp
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.
Affected products
- Nexusphp Project Nexusphp: version 1.5 only
Published 2017-09-07. Last modified 2026-06-17.