6.8
CVSSv2

CVE-2012-1498

Published: 19/03/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and previous versions allow remote malicious users to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name.

Vulnerable Product Search on Vulmon Subscribe to Product

nikola posa webfoliocms1.1.3

nikola posa webfoliocms1.0.5

nikola posa webfoliocms1.0.4

nikola posa webfoliocms1.1.2

nikola posa webfoliocms1.1.1

nikola posa webfoliocms1.0.3

nikola posa webfoliocms1.0.2

nikola posa webfoliocms1.1.0

nikola posa webfoliocms1.0.9

nikola posa webfoliocms1.1.4

nikola posa webfoliocms1.0.8

nikola posa webfoliocms1.0.7

nikola posa webfoliocms1.0.6

Exploits

+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : WebfolioCMS <= 114 CSRF (Add Admin/Modify Pages) # Date : 28-02-2012 # Author : Ivano Binetti (ivanobinetticom) # Software link : sourceforgenet/project ...