CVE-2012-1901
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://secunia.com/advisories/48451
References
- http://ivanobinetti.blogspot.com/2012/03/flexcms-multiple-csrf-vulnerabilities.html
- http://secunia.com/advisories/48451
- http://www.exploit-db.com/exploits/18609
- http://ivanobinetti.blogspot.com/2012/03/flexcms-multiple-csrf-vulnerabilities.html
- http://secunia.com/advisories/48451
- http://www.exploit-db.com/exploits/18609
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.