PT-2008-5533 · Rianxosencabos · Rianxosencabos Cms

Cwh Underground

·

Published

2008-09-25

·

Updated

2017-09-29

·

CVE-2008-4245

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Rianxosencabos CMS version 0.9
Description: The issue concerns the Admin Control Panel, which does not require administrator privileges. This allows remote authenticated users to perform various administrative actions, including changing a user's privileges, deleting a user account, or other unspecified actions. These actions can be performed via vectors involving an admin lista action to the default URI, possibly related to the useradmin.php file.
Recommendations: For Rianxosencabos CMS version 0.9, consider restricting access to the Admin Control Panel to only authorized administrators until a fix is available. As a temporary workaround, limit the use of the admin lista action and access to the default URI to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4245

Affected Products

Rianxosencabos Cms