vendor:
Frog CMS
by:
10n1z3d
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Frog CMS
Affected Version From: 0.9.5
Affected Version To: 0.9.5
Patch Exists: YES
Related CWE: N/A
CPE: a:madebyfrog:frog_cms:0.9.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Frog CMS 0.9.5 Multiple CSRF Vulnerabilities
Frog CMS 0.9.5 is vulnerable to multiple CSRF attacks. An attacker can exploit this vulnerability to create an admin user, delete users, delete pages, delete snippets, delete layouts, and delete files (if the File Manager plugin is installed). The attacker can craft a malicious HTML page containing a form with hidden fields that will be automatically submitted when the page is loaded. The form will contain the parameters necessary to perform the desired action.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of Frog CMS.