CVE-2012-1248: Medium severity basercms mail vulnerability
app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2012-1248?
CVE-2012-1248 allows remote attackers to hijack sessions, potentially compromising administrative access.
How does CVE-2012-1248 affect shared-hosting environments?
CVE-2012-1248 specifically impacts shared-hosting environments where multiple installations are present, increasing the risk of session hijacking.
What versions of baserCMS are affected by CVE-2012-1248?
CVE-2012-1248 affects baserCMS versions 1.6.15 and earlier, including various 1.5.x versions.
How can I mitigate the effects of CVE-2012-1248?
To mitigate CVE-2012-1248, it is recommended to upgrade to the latest version of baserCMS that has addressed this vulnerability.
What is the recommended action for users of baserCMS 1.6.15 and earlier concerning CVE-2012-1248?
Users of baserCMS 1.6.15 and earlier should immediately update to a patched version to avoid vulnerability exploitation.