PT-2010-4949 · Mojoportal · Mojoportal
George Birbilis
·
Published
2010-09-24
·
Updated
2017-08-17
·
CVE-2010-3603
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mojoPortal versions 2.3.4.3 through 2.3.5.1
Description
A cross-site request forgery (CSRF) issue exists in the file manager service, specifically in the Services/FileService.ashx endpoint. This allows remote attackers to hijack the authentication of administrators, enabling them to rename arbitrary files. For example, an attacker could cause the user.config file to be moved, resulting in a denial of service (service stop) and potentially exposing sensitive information.
Recommendations
For versions 2.3.4.3 and 2.3.5.1, consider disabling the Services/FileService.ashx endpoint until a patch is available to prevent exploitation of the CSRF vulnerability. Restrict access to the file manager service to minimize the risk of unauthorized file modifications.
Exploit
Fix
DoS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mojoportal