vendor:
CMS Made Simple 1.7
by:
Pratul Agrawal
8,8
CVSS
HIGH
Cross Site Request Forgery (CSRF)
352
CWE
Product Name: CMS Made Simple 1.7
Affected Version From: 1.7
Affected Version To: 1.7
Patch Exists: Yes
Related CWE: N/A
CPE: a:cms_made_simple:cms_made_simple:1.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: php
2020
CMS Made Simple 1.7 CSRF Vulnerability
A Cross Site Request Forgery (CSRF) vulnerability was found in CMS Made Simple 1.7. An attacker could exploit this vulnerability by crafting a malicious HTML page that, when visited by an authenticated user, would add an admin user to the CMS Made Simple 1.7 system. The malicious HTML page would contain a form with hidden fields that would submit the user credentials to the adduser.php page. The attacker could then use the newly created admin user to gain access to the CMS Made Simple 1.7 system.
Mitigation:
To mitigate this vulnerability, users should ensure that they are running the latest version of CMS Made Simple 1.7 and that they are using strong passwords for their admin accounts.