PT-2012-3639 · Flexcms · Flexcms

Ivano Binetti

·

Published

2012-09-18

·

Updated

2013-09-05

·

CVE-2012-1901

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FlexCMS versions 3.2.1 and earlier
Description The issue allows remote attackers to hijack user authentication for requests that change account settings via a request to "index.php/profile-edit-save" or hijack administrator authentication for requests that add a new page via a request to "admin/pages-new-save".
Recommendations For FlexCMS versions 3.2.1 and earlier, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the "index.php/profile-edit-save" and "admin/pages-new-save" API endpoints until a patch is available. Avoid using these endpoints in a way that could allow unauthorized changes to account settings or addition of new pages.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1901

Affected Products

Flexcms