PT-2004-2607 · Fusion · Fusion News
Published
2004-07-30
·
Updated
2024-02-08
·
CVE-2004-1703
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Fusion News version 3.6.1
Description
The issue allows remote attackers to add user accounts if the administrator is logged in. This can be achieved by including an img bbcode tag in a comment that calls
index.php with the signup action. The action is executed when the administrator's browser loads the page containing the img tag.Recommendations
For Fusion News version 3.6.1, consider disabling the execution of the
signup action in index.php to prevent unauthorized user account additions until a patch is available. Restrict access to the administrator's account and ensure that comments are thoroughly validated to prevent malicious bbcode tags.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fusion News