PT-2007-6989 · Vigile · Vigilecms

Devilauron

·

Published

2007-11-22

·

Updated

2018-10-15

·

CVE-2007-6087

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VigileCMS version 1.4
Description A cross-site request forgery issue exists, allowing remote attackers to modify the admin password by manipulating certain parameters to the changepass module in index.php.
Recommendations For VigileCMS version 1.4, consider disabling access to the changepass module in index.php until a fix is available to prevent unauthorized password changes.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6087

Affected Products

Vigilecms