Cross-Site Request Forgery Vulnerability in BaserCMS Plugin by BaserCMS
CVE-2016-4881

8.8HIGH

Key Information:

Vendor
CVE Published:
12 May 2017

What is CVE-2016-4881?

The BaserCMS Plugin Blog prior to version 3.0.10 is susceptible to a cross-site request forgery (CSRF) vulnerability, which enables remote attackers to exploit weaknesses in the plugin. This can lead to the unauthorized hijacking of administrator authentication, allowing malicious users to perform actions on behalf of an authenticated admin without their consent. It is critical that users update to the latest version to mitigate potential exploitation.

Affected Version(s)

baserCMS plugin Blog version 3.0.10 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.