CVE-2012-4773: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an add action to admin/accounts/add/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4773?
CVE-2012-4773 is considered to be of medium severity due to its ability to facilitate unauthorized administrative actions through CSRF.
How do I fix CVE-2012-4773?
To fix CVE-2012-4773, upgrade Subrion CMS to version 2.2.3 or later to mitigate the vulnerabilities.
What types of actions can be hijacked by CVE-2012-4773?
CVE-2012-4773 allows attackers to potentially hijack the authentication of administrators to add, delete, or modify sensitive information.
Which versions of Subrion CMS are affected by CVE-2012-4773?
CVE-2012-4773 affects Subrion CMS versions prior to 2.2.3, including 2.0.4, 2.2.0, 2.2.1, and 2.2.2.
What vulnerability type does CVE-2012-4773 represent?
CVE-2012-4773 represents a cross-site request forgery (CSRF) vulnerability.