PT-2013-5476 · Ritecms · Ritecms
Published
2013-08-20
·
Updated
2017-08-29
·
CVE-2013-5316
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RiteCMS version 1.0.0
Description
A cross-site request forgery issue allows remote attackers to hijack the authentication of administrators for requests that change the administrator password. This is done via an edit user action to "cms/index.php".
Recommendations
For RiteCMS version 1.0.0, update to a version that includes a fix for this issue, as using the current version may allow attackers to change administrator passwords without authorization.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ritecms