PT-2007-6782 · Sblog · Sblog

Publicado

2007-11-05

·

Atualizado

2018-10-15

·

CVE-2007-5818

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sBlog version 0.7.3 Beta
Description A cross-site request forgery issue allows remote attackers to modify arbitrary blocks with administrator privileges.
Recommendations For sBlog version 0.7.3 Beta, consider implementing proper CSRF token validation to prevent unauthorized requests. As a temporary workaround, restrict access to the blocks edit do.php file to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5818

Produtos afetados

Sblog