PT-2009-2023 · Implied By Design · Micro Cms
Staker
·
Published
2009-03-30
·
Updated
2017-09-29
·
CVE-2008-6553
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Implied by Design Micro CMS (Micro-CMS) version 3.5 (aka 0.3.5)
Description
The issue allows remote attackers to perform certain actions without requiring authentication as an administrator. This includes creating administrative accounts via an "add admin" action, removing administrative accounts via a "delete admin" action, and modifying administrative passwords via a "change password" action.
Recommendations
For Implied by Design Micro CMS (Micro-CMS) version 3.5 (aka 0.3.5), consider implementing proper authentication mechanisms to restrict access to administrative actions, such as "add admin", "delete admin", and "change password", until a patch is available. As a temporary workaround, restrict access to the microcms-admin-home.php file to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro Cms