PT-2009-2023 · Implied By Design · Micro Cms
Staker
·
Publicado
2009-03-30
·
Atualizado
2017-09-29
·
CVE-2008-6553
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Implied by Design Micro CMS (Micro-CMS) version 3.5 (aka 0.3.5)
Description
The issue allows remote attackers to perform certain actions without requiring authentication as an administrator. This includes creating administrative accounts via an "add admin" action, removing administrative accounts via a "delete admin" action, and modifying administrative passwords via a "change password" action.
Recommendations
For Implied by Design Micro CMS (Micro-CMS) version 3.5 (aka 0.3.5), consider implementing proper authentication mechanisms to restrict access to administrative actions, such as "add admin", "delete admin", and "change password", until a patch is available. As a temporary workaround, restrict access to the microcms-admin-home.php file to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Micro Cms