CVE-2010-2039
Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php.
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- gpeasy/gpeasy cms
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1004-exploits/gpeasy-xsrf.txtExploit
- http://secunia.com/advisories/39643Vendor Advisory
- http://www.exploit-db.com/exploits/12441Exploit
- http://www.osvdb.org/64130
- http://www.vupen.com/english/advisories/2010/1030Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58214
- http://packetstormsecurity.org/1004-exploits/gpeasy-xsrf.txtExploit
- http://secunia.com/advisories/39643Vendor Advisory
- http://www.exploit-db.com/exploits/12441Exploit
- http://www.osvdb.org/64130
- http://www.vupen.com/english/advisories/2010/1030Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58214
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.