vendor:
Admidio
by:
Nawaf Alkeraithe
3.3
CVSS
LOW
Cross-Site Request Forgery
352
CWE
Product Name: Admidio
Affected Version From: 3.3.2005
Affected Version To: 3.3.2005
Patch Exists: NO
Related CWE:
CPE: a:admidio:admidio:3.3.5
Platforms Tested: PHP
2018
Admidio 3.3.5 – Cross-Site Request Forgery (Change Permissions)
Low privilege users are able to increase their permissions due to improper origin checking by the vendor.
Mitigation:
Implement proper origin checking and validation for requests.