CVE-2014-9459: CSRF
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107admin/users.php in e107 2.0 alpha2 allows remote attackers to hijack the authentication of administrators for requests that add users to the administrator group via the id parameter in an admin action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9459?
CVE-2014-9459 is classified as a high severity vulnerability due to its potential to allow remote attackers to hijack administrator authentication.
How do I fix CVE-2014-9459?
To fix CVE-2014-9459, it is recommended to update e107 CMS to a version that does not contain this vulnerability.
What type of vulnerability is CVE-2014-9459?
CVE-2014-9459 is a cross-site request forgery (CSRF) vulnerability.
Which software is affected by CVE-2014-9459?
CVE-2014-9459 specifically affects e107 version 2.0 alpha2.
What is the impact of CVE-2014-9459?
The impact of CVE-2014-9459 allows attackers to add unauthorized users to the administrator group.