CVE-2015-6655: CSRF
Published Aug 31, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/adminusers.php.
Affected Software
1 affected component
Pligg Pligg CMS=2.0.2
Event History
Aug 31, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6655?
The severity of CVE-2015-6655 is classified as medium, due to the potential for unauthorized actions by attackers.
2
How do I fix CVE-2015-6655?
To mitigate CVE-2015-6655, it's recommended to upgrade to the latest version of Pligg CMS that includes CSRF protections.
3
Who is affected by CVE-2015-6655?
Administrators using Pligg CMS version 2.0.2 are affected by CVE-2015-6655.
4
What type of attack does CVE-2015-6655 involve?
CVE-2015-6655 involves a cross-site request forgery (CSRF) attack, which can hijack administrator authentication.
5
Can CVE-2015-6655 allow remote access to my system?
Yes, CVE-2015-6655 can allow remote attackers to perform unauthorized actions on behalf of an administrator.