PT-2017-17970 · Bigtree · Bigtree Cms

Cdxy

·

Publicado

2017-04-15

·

Atualizado

2017-04-21

·

CVE-2017-7881

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BigTree CMS versions prior to 4.2.18
Description The issue allows remote attackers to bypass CSRF protection by manipulating the HTTP Referer header. This is due to the reliance on a substring check for CSRF protection, which can be exploited by placing the required admin/developer/ URI within a query string in the Referer header. The vulnerability was found in the core/admin/modules/developer/ header.php file and was patched in the core/inc/bigtree/admin.php file.
Recommendations For BigTree CMS versions prior to 4.2.18, update to version 4.2.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin/developer/ URI to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7881

Produtos afetados

Bigtree Cms