vendor:
SocialCMS
by:
vir0e5 a.k.a banditc0de
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: SocialCMS
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:socialcms:socialcms:1.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
socialcms1.0.2 Multiple CSRF Vulnerabilities
The SocialCMS 1.0.2 application is vulnerable to multiple CSRF attacks. An attacker can exploit this vulnerability to create an admin user, change the default site title, and perform other malicious activities.
Mitigation:
Implementing CSRF protection tokens, validating input, and using a web application firewall can help mitigate the risk of CSRF attacks.