First published: Tue Sep 18 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RealFlex RealWin | <=3.2.1 | |
RealFlex RealWin | =2.0 | |
RealFlex RealWin | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1901 is rated as a high severity vulnerability due to its potential to allow unauthorized changes to user account settings.
To fix CVE-2012-1901, update FlexCMS to version 3.2.2 or later, which addresses the CSRF vulnerabilities.
CVE-2012-1901 allows remote attackers to perform cross-site request forgery attacks that could hijack user and administrator sessions.
CVE-2012-1901 affects FlexCMS versions 3.2.1 and earlier, as well as versions 2.0 and 2.5.
Yes, CVE-2012-1901 poses a significant risk to web application security by enabling unauthorized actions through forged requests.