X3 CMS CVE-2014-8771 Multiple Cross Site Request Forgery Vulnerabilities
BID:71513
Info
X3 CMS CVE-2014-8771 Multiple Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 71513 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8771 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2014 12:00AM |
| Updated: | Nov 08 2014 12:00AM |
| Credit: | Narendra Bhati |
| Vulnerable: |
X3cms X3 Cms 0.5.1.1 X3cms X3 Cms 0.5.1 |
| Not Vulnerable: |
X3cms X3 Cms 0.5.2 |
Discussion
X3 CMS CVE-2014-8771 Multiple Cross Site Request Forgery Vulnerabilities
X3 CMS is prone to multiple cross-site request-forgery vulnerabilities because it does not properly validate HTTP requests.
An attacker can exploit these issues to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
X3 CMS versions 0.5.1, and 0.5.1.1 are vulnerable.
X3 CMS is prone to multiple cross-site request-forgery vulnerabilities because it does not properly validate HTTP requests.
An attacker can exploit these issues to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
X3 CMS versions 0.5.1, and 0.5.1.1 are vulnerable.
Exploit / POC
X3 CMS CVE-2014-8771 Multiple Cross Site Request Forgery Vulnerabilities
To exploit these issues an attacker must entice a user into visiting a malicious site.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
To exploit these issues an attacker must entice a user into visiting a malicious site.
The researcher who discovered these issues has created a proof-of-concept. Please see the references for more information.
References
X3 CMS CVE-2014-8771 Multiple Cross Site Request Forgery Vulnerabilities
References:
References:
- X3 CMS 0.5.2 - Security fixes (x3cms)
- X3 CMS Homepage (X3 CMS)
- X3 CMS XSS And CSRF �??CVE-2014-8771 , CVE-2014-8772? (websecgeeks)