MEDIUM
Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter
Published Dec 3, 2012
6.8
MEDIUMCVSS 2.0
EPSS 0.87%
Description
Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter.
Affected products
No data.
OR
- ≤ 1.11.2
- 0.1
- 0.2
- 0.2.1
- 0.3
- 0.3.1
- 0.3.2
- 0.4
- 0.4.1
- 0.5
- 0.5.1
- 0.6
- 0.6.1
- 0.6.2
- 0.6.3
- 0.7
- 0.7.1
- 0.7.2
- 0.7.3
- 0.8
- 0.8.1
- 0.8.2
- 0.9
- 0.9.1
- 0.9.2
- 0.10
- 0.10.1
- 0.10.2
- 0.10.3
- 0.10.4
- 0.11
- 0.11.1
- 0.11.2
- 0.12
- 0.12.1
- 0.12.2
- 0.13
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.3.1
- 1.1.4
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.3
- 1.3
- 1.3
- 1.4
- 1.4.1
- 1.5
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.6
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.7
- 1.7.1
- 1.8
- 1.8.1
- 1.8.2
- 1.9
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.9.4.1
- 1.9.4.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://archives.neohapsis.com/archives/bugtraq/2012-11/0035.html mailing-listx_refsource_BUGTRAQExploit
- http://forum.cmsmadesimple.org/viewtopic.php?f=1&t=63545 x_refsource_CONFIRM
- http://packetstormsecurity.org/files/117951/CMS-Made-Simple-1.11.2-Cross-Site-Request-Forgery.html x_refsource_MISCExploit
- http://secunia.com/advisories/51185 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://viewsvn.cmsmadesimple.org/diff.php?repname=cmsmadesimple&path=%2Ftrunk%2Flib%2Ffilemanager%2FImageManager%2FClasses%2FImageManager.php&rev=8400&peg=8498 x_refsource_CONFIRM
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79881 vdb-entryx_refsource_XF
- https://www.htbridge.com/advisory/HTB23121 x_refsource_MISCExploit
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2012-11/0035.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://forum.cmsmadesimple.org/viewtopic.php?f=1&t=63545 | x_refsource_CONFIRM | |
| http://packetstormsecurity.org/files/117951/CMS-Made-Simple-1.11.2-Cross-Site-Request-Forgery.html | x_refsource_MISCExploit | |
| http://secunia.com/advisories/51185 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://viewsvn.cmsmadesimple.org/diff.php?repname=cmsmadesimple&path=%2Ftrunk%2Flib%2Ffilemanager%2FImageManager%2FClasses%2FImageManager.php&rev=8400&peg=8498 | x_refsource_CONFIRM | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/79881 | vdb-entryx_refsource_XF | |
| https://www.htbridge.com/advisory/HTB23121 | x_refsource_MISCExploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 3, 2012
Updated Aug 6, 2024
Reserved Oct 17, 2012
Link CVE-2012-5450
CISA Vulnrichment
Updated n/a