Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
BID:55766
Info
Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 55766 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4901 CVE-2012-4902 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2012 12:00AM |
| Updated: | Oct 03 2012 12:00AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Template CMS is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add, delete or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Template CMS 2.1.1 and prior versions are vulnerable.
Template CMS is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add, delete or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Template CMS 2.1.1 and prior versions are vulnerable.
Exploit / POC
Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI or visit a malicious website.
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI or visit a malicious website.
Solution / Fix
Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Template CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
References:
References:
- Template CMS Homepage (Template CMS)
- Multiple vulnerabilities in Template CMS (High-Tech Bridge)