6.8
CVSSv2

CVE-2015-1424

Published: 29/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote malicious users to hijack the authentication of administrators for requests that add an administrator user via a newuser request to admin/index.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jakweb gecko cms 2.2

jakweb gecko cms 2.3

Exploits

Gecko CMS 23 Multiple Vulnerabilities Vendor: JAKWEB Product web page: wwwcmsgeckocom Affected version: 23 and 22 Summary: Gecko CMS is the way to go, forget complicated, bloated and slow content management systems, Gecko CMS has been build to be intuitive, easy to use, extendable to almost anything, running on all standard web hostin ...