vendor:
RazorCMS
by:
Ivano Binetti
7,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: RazorCMS
Affected Version From: 1.2.1 STABLE and lower
Affected Version To: 1.2.1 STABLE and lower
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian Squeeze (6.0)
2012
RazorCMS <= 1.2.1 STABLE CSRF (Delete Web Pages)
RazorCMS 1.2.1 STABLE (and lower) is affected by CSRF Vulnerability which allows an attacker to delete web pages, both published and unpublished. An attacker can craft a malicious HTML page containing a form with the action attribute set to the URL of the vulnerable page, and when the victim visits the malicious page, the form will be automatically submitted, resulting in the deletion of the web page.
Mitigation:
Developers should ensure that all user input is properly validated and sanitized. Additionally, developers should ensure that all user input is properly validated and sanitized. Furthermore, developers should ensure that all user input is properly validated and sanitized.