vendor:
DubSite CMS
by:
Connection
7.5
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: DubSite CMS
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:dubsite:dubsite_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2009
Cross Site Request Forgery(CSRF) vulnerability in DubSite CMS v1.0
Due to the lack of multiple input validation errors, an attacker is able to change the password of the administrative user. The following link will change the password of the administrative account. Changing the options will also allow you to change the name of the admin account. This link creates a user 'hax0r' with password test123 and adds it to the administrator group.
Mitigation:
To fix the bugs a token system is highly advised.