Elefant CMS 1.3.12-RC CSRF

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 1. Introduction ``` Affected Product: Elefant CMS 1.3.12-RC Fixed in: 1.3.13 Fixed Version Link: https://github.com/jbroadway/elefant/releases/tag/elefant_1_3_13_rc Vendor Website: https://www.elefantcms.com/ Vulnerability Type: CSRF Remote Exploitable: Yes Reported to vendor: 09/05/2016 Disclosed to public: 02/02/2017 Release mode: Coordinated Release CVE: n/a (not requested) Credits Tim Coen of Curesec GmbH ``` ### 2. Overview Elefant is a content managment system written in PHP. In version 1.3.12-RC, it is vulnerable to cross site request forgery. If a victim visits a website that contains specifically crafted code while logged into Elefant, an attacker can for example create a new admin account without the victims knowledge. ### 3. Details CVSS: Medium 5.1 AV:N/AC:H/Au:N/C:P/I:P/A:P There is no CSRF protection for various components, allowing among other the creation of new admin accounts or XSS attacks. Proof of Concept: Create New Admin: ``` Create New Admin: <html>...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息