CVE-2008-7243
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php.
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- modxcms/modxcms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28840Vendor Advisory
- http://www.securityfocus.com/archive/1/487696/100/200/threaded
- http://www.securityfocus.com/bid/27672Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40378
- http://secunia.com/advisories/28840Vendor Advisory
- http://www.securityfocus.com/archive/1/487696/100/200/threaded
- http://www.securityfocus.com/bid/27672Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40378
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.