vendor:
CMSUno
by:
Noth
7.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: CMSUno
Affected Version From: v1.6
Affected Version To: v1.6.1
Patch Exists: YES
Related CWE: 2020-15600
CPE: a:boiteasite:cmsuno
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
CMSUno 1.6 – Cross-Site Request Forgery (Change Admin Password)
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. The PoC code provided allows an attacker to submit a request to the uno.php page with a new admin password.
Mitigation:
Ensure that all requests are validated and authenticated before being processed.