First published: Tue Feb 05 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | =4.01.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0575 is classified as a high severity vulnerability due to its potential to grant unauthorized superadmin privileges.
To fix CVE-2008-0575, update to a version of webSPELL that patches this CSRF vulnerability.
CVE-2008-0575 is a Cross-Site Request Forgery (CSRF) vulnerability.
Any webSPELL 4.01.02 user with an administrative interface is at risk of being affected by CVE-2008-0575.
Attackers can exploit CVE-2008-0575 to assign the superadmin privilege level to arbitrary user accounts.