First published: Fri Oct 08 2010(Updated: )
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple | <=1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3884 has a moderate severity rating due to its potential for unauthorized administrative password resets.
To fix CVE-2010-3884, upgrade your CMS Made Simple installation to version 1.8.2 or later, which addresses the CSRF vulnerability.
CVE-2010-3884 affects users of CMS Made Simple version 1.8.1 and earlier.
CVE-2010-3884 is a cross-site request forgery (CSRF) vulnerability.
Attackers exploiting CVE-2010-3884 can hijack administrator sessions to reset passwords and potentially take control of the CMS.