![CMS Made Simple](http://www.cmsmadesimple.org/uploads/new/new_sublogo24.png)
CMS Made Simple (version 1.11.2), an open source CMS, contain vulnerability which can be exploited to perform cross-site request forgery (CSRF) attacks.
The application allows authorized administrator to perform certain actions via HTTP requests without making proper validity checks to verify the source of the requests. This can be exploited to delete arbitrary files and directories. An attacker should make logged-in administrator open a malicious link in the browser to exploit this vulnerability.
PoC (Proof of Concept) code for this advisory will delete the root directory with all files leading to complete destroy of the CMS (when additional conditions satisfied).
Vulnerability is fixed at this moment, upgrade to CMSMS 1.11.2.1
High-Tech Bridge Advisory HTB23121 - Сross-Site Request Forgery (CSRF) in CMS Made Simple.
No comments:
Post a Comment