PT-2015-3658 · Phpjabbers · Phpjabbers Event Booking Calendar

Publicado

2015-01-13

·

Atualizado

2017-09-08

·

CVE-2014-10014

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHPJabbers Event Booking Calendar version 2.0
Description The issue affects the authentication of administrators, allowing remote attackers to hijack it for requests. This can be achieved through multiple cross-site request forgery (CSRF) vulnerabilities. Specifically, attackers can change the administrator's username and password via an update action to the "AdminOptions" controller. Additionally, cross-site scripting (XSS) attacks can be conducted using the event title parameter in a create action to the "AdminEvents" controller or the category title parameter in a create action to the "AdminCategories" controller.
Recommendations For PHPJabbers Event Booking Calendar version 2.0, consider disabling the update action to the AdminOptions controller, and restrict access to the create actions in the AdminEvents and AdminCategories controllers to minimize the risk of exploitation. Avoid using the event title and category title parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-10014

Produtos afetados

Phpjabbers Event Booking Calendar