CVE-2019-9040: S-CMS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.
Affected products
- S-CMS S-CMS: version 3.0 only
Published 2019-02-23. Last modified 2026-06-17.