vendor:
Pligg CMS
by:
Arash Khazaei
7,5
CVSS
HIGH
CSRF
352
CWE
Product Name: Pligg CMS
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE: CVE-2015-6655
CPE: 2.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali, Iceweasel Browser
2015
Pligg CMS CSRF Add Admin Exploit
Pligg CMS is a CMS written in PHP language and licensed under GPL v 2.0. In Pligg CMS panel in adding users section Pligg CMS allow to attacker add admin by CSRF vulnerability. The vulnerability in add users sections and another thing is added admin by CSRF vulnerability can't be deleted by admin and admin should delete it from database.
Mitigation:
Admin should delete the added user from the database.