Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for requests that create a web page containing PHP code.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://secunia.com/advisories/34744 | third party advisory vendor advisory |
http://razorcms.co.uk/support/viewtopic.php?f=13&t=325 | vendor advisory |
http://osvdb.org/53778 | vdb entry |
http://marc.info/?l=full-disclosure&m=123998062108561&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49947 | vdb entry |
http://marc.info/?l=full-disclosure&m=123990481506680&w=2 | mailing list |
http://www.securityfocus.com/bid/34566 | vdb entry |