CVE-2016-4879: CSRF
Published May 12, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Affected Software
2 affected components
baserCMS BaserCMS<=3.0.10
baserCMS Mail Basercms<=3.0.10
Remediation
Patch Available
Event History
May 12, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4879?
CVE-2016-4879 is classified as a moderate severity vulnerability due to its potential for cross-site request forgery attacks.
2
How do I fix CVE-2016-4879?
To fix CVE-2016-4879, upgrade the baserCMS plugin Mail to version 3.0.11 or later.
3
Who is affected by CVE-2016-4879?
CVE-2016-4879 affects users of baserCMS Mail plugin version 3.0.10 and earlier.
4
What type of attack is possible with CVE-2016-4879?
CVE-2016-4879 allows remote attackers to perform cross-site request forgery attacks to hijack administrators' authentication.
5
What versions of baserCMS are vulnerable to CVE-2016-4879?
Versions of baserCMS up to and including 3.0.10 are vulnerable to CVE-2016-4879.