First published: Wed Dec 02 2009(Updated: )
Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for requests that create new users, including a new administrator, via an adduser action in the editusers module in index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CutePHP CuteNews | =1.4.6 | |
Korn19 Utf-8 Cutenews | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4173 is classified as a medium severity vulnerability due to the potential for unauthorized access and user creation.
To fix CVE-2009-4173, upgrade to the latest version of CuteNews or apply a patch that mitigates CSRF vulnerabilities.
CVE-2009-4173 affects CuteNews version 1.4.6 and UTF-8 CuteNews versions prior to 8b.
CVE-2009-4173 involves a cross-site request forgery (CSRF) attack that can hijack administrator authentication.
Yes, CVE-2009-4173 can allow remote attackers to create new users, including new administrators, through an unauthenticated request.