Cross-Site Request Forgery Vulnerabilities in Wolf CMS by Wolf CMS
CVE-2012-1897

Currently unrated

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
1 October 2012

What is CVE-2012-1897?

Wolf CMS versions 0.75 and earlier are subject to multiple cross-site request forgery (CSRF) vulnerabilities that empower remote attackers to perform unauthorized actions. These vulnerabilities facilitate the hijacking of administrator sessions, enabling actions such as user deletions via ID, page deletions, and the removal of directories containing images or themes. In addition, attackers can force logouts by sending crafted requests. These security flaws put the integrity and availability of the web application at risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.