UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
BID:59742
Info
UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 59742 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2754 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2013 12:00AM |
| Updated: | May 08 2013 12:00AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
UMI CMS is prone a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
UMI CMS 2.9 is vulnerable, other versions may also be affected.
UMI CMS is prone a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
UMI CMS 2.9 is vulnerable, other versions may also be affected.
Exploit / POC
UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
UMI CMS CVE-2013-2754 Cross-Site Request Forgery Vulnerability
References:
References:
- UMI CMS Homepage (UMI CMS)