vendor:
Ektron Content Management System
by:
Jerold Hoong
7.5
CVSS
HIGH
Cross-site Request Forgery
352
CWE
Product Name: Ektron Content Management System
Affected Version From: N/A
Affected Version To: 9.10 SP1 (Build 9.1.0.184.1.120)
Patch Exists: YES
Related CWE: CVE-2015-3624
CPE: a:ektron:ektron_cms:9.10_sp1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Cross-site Request Forgery
Cross-site request forgery (CSRF) vulnerability in MenuActions.aspx in Ektron CMS 9.10 SP1 before build 9.1.0.184.1.120 allows remote attackers to hijack the authentication of content administrators for requests that could lead to the deletion of content and assets.
Mitigation:
The vendor has released a patch to address this vulnerability.