CVE-2008-7221: CSRF
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests that (1) add new administrators or (2) modify user profiles via a crafted request to system/admin.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7221?
CVE-2008-7221 is considered a high severity vulnerability due to its potential to allow unauthorized access and modifications by remote attackers.
How do I fix CVE-2008-7221?
To fix CVE-2008-7221, it is recommended to upgrade to a patched version of RunCMS or implement CSRF protection mechanisms in your web application.
Who is affected by CVE-2008-7221?
CVE-2008-7221 affects users running RunCMS version 1.6.1, particularly those with administrative access.
What can attackers do with CVE-2008-7221?
Attackers exploiting CVE-2008-7221 can hijack administrator authentication and potentially modify user profiles or add new administrators.
What type of vulnerability is CVE-2008-7221?
CVE-2008-7221 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.