CVE-2019-15229: CSRF
Published Aug 19, 2019
·Updated
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS<=1.4.4
Event History
Aug 19, 2019
CVE Published
via MITRE·11:29 PM
Data Sourced
via MITRE·11:29 PM
Description
Frequently Asked Questions
1
What is CVE-2019-15229?
CVE-2019-15229 is a vulnerability found in FUEL CMS 1.4.4 that allows for CSRF attacks in the blocks/create section of the Admin console.
2
How does CVE-2019-15229 affect FUEL CMS?
CVE-2019-15229 allows an attacker to trick the administrator into executing arbitrary code via a specially crafted HTML page.
3
What is the severity of CVE-2019-15229?
CVE-2019-15229 has a severity rating of 8.8 (high).
4
How can I fix CVE-2019-15229?
To fix CVE-2019-15229, it is recommended to upgrade to a version of FUEL CMS that does not have this vulnerability.
5
Where can I find more information about CVE-2019-15229?
More information about CVE-2019-15229 can be found in the GitHub issue and the Seven Layers website.