vendor:
Family CMS
by:
Ahmed Elhady Mohamed
3,3
CVSS
MEDIUM
CSRF and XSS
352,79
CWE
Product Name: Family CMS
Affected Version From: 2.9
Affected Version To: 2.9
Patch Exists: NO
Related CWE: N/A
CPE: 2.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 11.4
2020
Family CMS 2.9 and earlier multiple Vulnerabilities
Family CMS 2.9 and earlier is vulnerable to CSRF and XSS. For CSRF, the POCs are provided in the text. For XSS, the POC is provided in the text.
Mitigation:
Implementing CSRF tokens and validating user input to prevent XSS attacks.