CVE-2008-3203: High severity tina tinacms vulnerability
Published Jul 17, 2008
·Updated
js/pages/pagesdata.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
Affected Software
3 affected components
AuraCMS AuraCMS=2.2.2
AuraCMS AuraCMS=2.2.1
AuraCMS AuraCMS=2.2
Event History
Jul 17, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3203?
CVE-2008-3203 is considered to have a high severity due to its potential to allow unauthorized modifications to web content.
2
How do I fix CVE-2008-3203?
To fix CVE-2008-3203, upgrade to AuraCMS version 2.2.3 or later, which includes authentication measures.
3
What systems are affected by CVE-2008-3203?
CVE-2008-3203 affects AuraCMS versions 2.2, 2.2.1, and 2.2.2.
4
What type of attack does CVE-2008-3203 enable?
CVE-2008-3203 enables remote attackers to add, edit, and delete web content without authentication.
5
Is there a workaround for CVE-2008-3203?
A temporary workaround for CVE-2008-3203 includes restricting access to the pages_data.php file until a patch is applied.