CVE-2017-16244
Dashboard / Vulnerabilities / CVE-2017-16244
Summary:
Details: Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.
References: https://github.com/octobercms/october/commit/4a6e0e1e0e2c3facebc17e0db38c5b4d4cb05bd0, https://www.exploit-db.com/exploits/43106/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- de9804c8974d36a250b0059be141292021ff02bd
Fixed -None
Affected versions
1.0.426
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
