CVE-2014-4718
03.07.2014, 14:55
Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks via the (2) email or (3) subject parameter in contact_form.ext.php to admin/extensions.php.
Vendor | Product | Version |
---|---|---|
lunarcms | lunar_cms | 𝑥 ≤ 3.3 |
lunarcms | lunar_cms | 3.1 |
lunarcms | lunar_cms | 3.2 |
lunarcms | lunar_cms | 3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References