vendor:
Mambo CMS
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Mambo CMS
Affected Version From: 4.6.2005
Affected Version To: 4.6.2005
Patch Exists: NO
Related CWE:
CPE: a:mambo-foundation:mambo:4.6.5
Platforms Tested:
2011
Cross-Site Request Forgery in Mambo CMS
Mambo CMS is prone to a cross-site request-forgery vulnerability. Attackers can exploit this issue by tricking an unsuspecting user into visiting a malicious Web page. The page will consist of specially crafted script code designed to perform some action on the attacker's behalf. Successful exploits will allow attackers to run privileged commands on the affected device.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of Mambo CMS or switch to a more secure CMS.