5.8
CVSSv2

CVE-2015-3624

Published: 09/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) prior to 9.10 SP1 (Build 9.1.0.184.1.120) allows remote malicious users to hijack the authentication of content administrators for requests that delete content via a delete action.

Vulnerable Product Search on Vulmon Subscribe to Product

ektron ektron content management system

Exploits

# Vulnerability type: Cross-site Request Forgery # Vendor: wwwektroncom/ # Product: Ektron Content Management System # Affected version: =< 910 SP1 (Build 9101841114) # Patched version: 910 SP1 (Build 9101841120) # CVE ID: CVE-2015-3624 # Credit: Jerold Hoong # PROOF OF CONCEPT (CSRF) Cross-site request forgery (CSRF) vul ...
Ektron CMS versions 910 SP1 build 9101841114 and below suffer from a cross site request forgery vulnerability ...