First published: Fri Sep 24 2010(Updated: )
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file to be moved, leading to a denial of service (service stop) and possibly the exposure of sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MojoPortal | =2.3.4.3 | |
MojoPortal | =2.3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3603 is considered a medium severity vulnerability due to its potential for cross-site request forgery attacks.
CVE-2010-3603 addresses a cross-site request forgery vulnerability in the file manager service of mojoPortal.
To fix CVE-2010-3603, update mojoPortal to versions 2.3.4.4 or 2.3.5.2 or later, which include security improvements.
CVE-2010-3603 affects users of mojoPortal versions 2.3.4.3 and 2.3.5.1.
CVE-2010-3603 can be exploited to hijack the authentication of administrators and perform unauthorized actions such as renaming files.