First published: Mon Sep 14 2009(Updated: )
Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests that (1) add new administrators or (2) modify user profiles via a crafted request to system/admin.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Runcms Runcms | =1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7221 is considered a high severity vulnerability due to its potential to allow unauthorized access and modifications by remote attackers.
To fix CVE-2008-7221, it is recommended to upgrade to a patched version of RunCMS or implement CSRF protection mechanisms in your web application.
CVE-2008-7221 affects users running RunCMS version 1.6.1, particularly those with administrative access.
Attackers exploiting CVE-2008-7221 can hijack administrator authentication and potentially modify user profiles or add new administrators.
CVE-2008-7221 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.