Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.
References
Link | Resource |
---|---|
http://packetstormsecurity.org/0909-exploits/cmsphp-xsrf.txt | Broken Link Exploit |
http://secunia.com/advisories/36075 | Broken Link Vendor Advisory |
Configurations
History
No history.
Information
Published : 2009-10-01 15:30
Updated : 2024-02-08 20:48
NVD link : CVE-2009-3520
Mitre link : CVE-2009-3520
CVE.ORG link : CVE-2009-3520
JSON object : View
Products Affected
cmsphp_project
- cmsphp
CWE
CWE-352
Cross-Site Request Forgery (CSRF)