vendor:
concrete5
by:
expl0i13r
7,5
CVSS
HIGH
CSRF (Modify SMTP Settings)
352
CWE
Product Name: concrete5
Affected Version From: 5.6.1.2
Affected Version To: 5.6.1.2
Patch Exists: NO
Related CWE: N/A
CPE: a:concrete5:concrete5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
concrete5 CMS v5.6.1.2 Multiple CSRF and Stored XSS Vulnerabilities
concrete5 v5.6.1.2 suffers from multiple CSRF vulnerabilities one of which allow an attacker to modify 'SMTP Settings' and 'Send Mail Method' available at http://127.0.0.1/concrete5.6.1.2/concrete5.6.1.2/index.php/dashboard/system/mail/method/
Mitigation:
Ensure that all user input is validated and sanitized before being used in any operation.