PT-2014-2707 · Kasseler · Kasseler Cms

Publicado

2014-03-13

·

Atualizado

2014-03-13

·

CVE-2013-3729

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kasseler CMS versions prior to 2 r1232
Description The issue allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks. This can be achieved via the groups[] parameter in a send action in the "sendmail" module or the query parameter in a "sql query" action in the "database" module to "admin.php".
Recommendations For versions prior to 2 r1232, update to version 2 r1232 or later to resolve the issue. As a temporary workaround, consider restricting access to the "sendmail" and "database" modules to minimize the risk of exploitation. Avoid using the groups[] and query parameters in the affected API endpoints until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3729

Produtos afetados

Kasseler Cms