vendor:
WBCE CMS
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Open Redirect & CSRF
CWE
Product Name: WBCE CMS
Affected Version From: 1.6.2001
Affected Version To: 1.6.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
WBCE CMS 1.6.1 – Open Redirect & CSRF
The WBCE CMS 1.6.1 version is vulnerable to an open redirect and cross-site request forgery (CSRF) attack. By uploading a specially crafted HTML file and tricking a logged-in user to visit a malicious URL, an attacker can exploit this vulnerability to perform CSS keylogging.
Mitigation:
The vendor should release a patch addressing the open redirect and CSRF vulnerabilities. Users are advised to update to the latest version of the software. Additionally, users should be cautious when clicking on untrusted links.