PT-2012-3639 · Flexcms · Flexcms
Ivano Binetti
·
Publicado
2012-09-18
·
Atualizado
2013-09-05
·
CVE-2012-1901
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FlexCMS versions 3.2.1 and earlier
Description
The issue allows remote attackers to hijack user authentication for requests that change account settings via a request to "index.php/profile-edit-save" or hijack administrator authentication for requests that add a new page via a request to "admin/pages-new-save".
Recommendations
For FlexCMS versions 3.2.1 and earlier, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the "index.php/profile-edit-save" and "admin/pages-new-save" API endpoints until a patch is available.
Avoid using these endpoints in a way that could allow unauthorized changes to account settings or addition of new pages.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flexcms