Cross-Site Request Forgery Vulnerability in baserCMS Blog Plugin by baserCMS
CVE-2016-4884

8.8HIGH

Key Information:

Vendor
CVE Published:
12 May 2017

What is CVE-2016-4884?

The baserCMS Blog plugin is vulnerable to a Cross-Site Request Forgery (CSRF) attack, which may allow remote attackers to exploit the authentication of administrators. The vulnerability exists in versions 3.0.10 and earlier of the plugin, enabling unauthorized users to perform actions on behalf of legitimate users without their consent. This issue can lead to unauthorized content modifications and potential control over the administrative functionalities, posing significant risks to the security of web applications using this plugin.

Affected Version(s)

baserCMS plugin Blog version 3.0.10 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.