vendor:
Simple PHP Agenda
by:
Ivano Binetti
7,5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Simple PHP Agenda
Affected Version From: 2.2.8 and lower
Affected Version To: 2.2.8 and lower
Patch Exists: YES
Related CWE: CVE-2012-1978
CPE: a:php_agenda:simple_php_agenda
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian Squeeze (6.0)
2012
Simple PHP Agenda <= 2.2.8 CSRF (Add Admin - Add Event)
Simple Php Agenda 2.2.8 (and lower) is affected by a CSRF Vulnerability which allows an attacker to add a new administrator, delete an existing administrator, create/delete a new event and change any other parameters. In this document, the author demonstrates how to add a new administrator, delete an existing administrator, add a new event, and delete an existing event.
Mitigation:
The vendor has released a patch to address this vulnerability.