vendor:
UMI.CMS
by:
High-Tech Bridge Security Research Lab
5,1
CVSS
MEDIUM
Cross-Site Request Forgery [CWE-352]
352
CWE
Product Name: UMI.CMS
Affected Version From: 2.9
Affected Version To: 2.9
Patch Exists: YES
Related CWE: CVE-2013-2754
CPE: OOO Umisoft/UMI.CMS
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Cross-site Request Forgery (CSRF) in UMI.CMS
The application allows authorized administrator to perform certain sensitive actions via HTTP requests without making proper validity checks to verify the source of these HTTP requests. This can be exploited to perform any actions with administrator privileges, such as adding new administrator to the system. A remote attacker can create a specially crafted webpage, trick a logged-in administrator to open it and create new user with administrative privileges.
Mitigation:
Fixed by Vendor