CVE-2008-7214: CSRF
Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add new administrator accounts via the save task in a comusers action, as demonstrated using a separate XSS vulnerability in mambots/editors/mostlyce/jscripts/tinymce/filemanager/connectors/php/connector.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7214?
CVE-2008-7214 has a medium severity rating due to its potential to allow unauthorized administrative access.
How do I fix CVE-2008-7214?
To fix CVE-2008-7214, update to Mambo version 4.6.4 or later, or ensure that your version of MOStlyCE is updated beyond 2.0.
Which software is affected by CVE-2008-7214?
CVE-2008-7214 affects Mambo versions up to 4.6.3 and MOStlyCE versions up to 2.0.
What type of attack does CVE-2008-7214 facilitate?
CVE-2008-7214 facilitates cross-site request forgery (CSRF) attacks that allow attackers to hijack administrator sessions.
Can I mitigate the risks of CVE-2008-7214 without upgrading?
Mitigating CVE-2008-7214 without upgrading is challenging, but implementing web application firewalls may help reduce risk until an upgrade can be performed.