CVE-2010-3884: CSRF
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3884?
CVE-2010-3884 has a moderate severity rating due to its potential for unauthorized administrative password resets.
How do I fix CVE-2010-3884?
To fix CVE-2010-3884, upgrade your CMS Made Simple installation to version 1.8.2 or later, which addresses the CSRF vulnerability.
Who is affected by CVE-2010-3884?
CVE-2010-3884 affects users of CMS Made Simple version 1.8.1 and earlier.
What type of attack is CVE-2010-3884?
CVE-2010-3884 is a cross-site request forgery (CSRF) vulnerability.
What can attackers achieve with CVE-2010-3884?
Attackers exploiting CVE-2010-3884 can hijack administrator sessions to reset passwords and potentially take control of the CMS.