First published: Mon Oct 22 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack the authentication of administrators for requests that add, delete, or modify sensitive information, as demonstrated by adding an administrator account via an add action to admin/accounts/add/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intelliants Subrion CMS | <=2.2.2 | |
Intelliants Subrion CMS | =2.0.4 | |
Intelliants Subrion CMS | =2.2.0 | |
Intelliants Subrion CMS | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4773 is considered to be of medium severity due to its ability to facilitate unauthorized administrative actions through CSRF.
To fix CVE-2012-4773, upgrade Subrion CMS to version 2.2.3 or later to mitigate the vulnerabilities.
CVE-2012-4773 allows attackers to potentially hijack the authentication of administrators to add, delete, or modify sensitive information.
CVE-2012-4773 affects Subrion CMS versions prior to 2.2.3, including 2.0.4, 2.2.0, 2.2.1, and 2.2.2.
CVE-2012-4773 represents a cross-site request forgery (CSRF) vulnerability.