PT-2007-4608 · Stphp · Stphp Easynews Pro

The Crew

·

Publicado

2007-06-21

·

Atualizado

2017-07-29

·

CVE-2007-3331

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions STphp EasyNews PRO version 4.0
Description A cross-site request forgery (CSRF) issue allows remote attackers to change the admin password. This can be achieved via a certain HTML form that is posted automatically by JavaScript or through a news post.
Recommendations For STphp EasyNews PRO version 4.0, consider disabling the ability to change the admin password via HTML forms posted by JavaScript or through news posts until a fix is available. Restrict access to admin password change functionality to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3331

Produtos afetados

Stphp Easynews Pro