vendor:
OpenCMS
by:
Sureshbabu Narvaneni
8.8
CVSS
HIGH
Cross-site request forgery (CSRF)
352
CWE
Product Name: OpenCMS
Affected Version From: 10.5.3
Affected Version To: 10.5.3
Patch Exists: YES
Related CWE: CVE-2018-8811
CPE: a:alkacon_software:opencms:10.5.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 14.04 x86_64/Kali Linux 4.12 i686
2018
OpenCMS 10.5.3 Multiple Cross Site Request Forgery Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administrative users for requests that perform privilege escalation.
Mitigation:
The user should be aware of the malicious requests and should not click on any suspicious links.