
We found results for “”
CVE-2019-13370
Good to know:

Date: July 6, 2019
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix

Upgrade Version
Upgrade to version rogeriopradoj/codeigniter - dev-upstream-develop;rogeriopradoj/codeigniter - dev-2.2-stable;rogeriopradoj/codeigniter - no_fix;rogeriopradoj/codeigniter - 2.2.1;robjuz/cakephp-kovicky - no_fix;opensource-workshop/connect-cms - v0.0.1.20201008;opensource-workshop/connect-cms - v0.0.1.20201207;opensource-workshop/connect-cms - v0.0.1.20210104;opensource-workshop/connect-cms - v0.0.1.20220207;opensource-workshop/connect-cms - dev-PageManage;bappa2du/fast - no_fix;iet-ou/open-media-player - 1.2;ellislab/codeigniter - 2.2.1;ellislab/codeigniter - 3.0.4;codeigniter/framework - 2.2.1;codeigniter/framework - 3.0.4;kodazzi/amazonas - no_fix;kodazzi/amazonas - v1.0.0-alpha;carlosocarvalho/xml-table-data-manager - no_fix;renanmpimentel/codeigniter_start - no_fix;pragmaticlinux/codeigniter - no_fix;codeigniter31/framework - 3.0.4;cappuccinodigital/cup-cms - no_fix;despark/igni-core - no_fix;hanischit/codeigniter-restserver - 2.7.2;nielbuys/framework - 3.0.4;chriskacerguis/codeigniter-restserver - 2.7.2;webdmg/system-c - v0.1.0;timexstudio/codeigniter-3-orm-twig - no_fix;livecms/livecms - dev-liveCommerce;ezrun/framework-standard-edition - no_fix;dark-prospect-games/facebook-ignited - v1.2.0;ardissoebrata/ci-beam - v1.1;acosf/archersys - 2.0.0;acosf/archersys - 2.0.1;vtlfokin/codeigniter - 2.2.1;rebekz/codeigniter_basic - no_fix;bcit-ci/codeigniter - 3.0.4;hjue/justwriting - v0.0.3;livecms/core - no_fix;webdmg/codeigniter - v0.1.0;rnkpatel/laravel-blog - no_fix;despark/ignicms - no_fix;schachbulle/contao-forum-bundle - 0.0.4;schachbulle/contao-forum-bundle - no_fix;savy/admin - 1.0.3;savy/admin - no_fix;tastyigniter/tastyigniter - v1.0.0;bappa2du/codeit - no_fix;maxtream/themages - no_fix;mawoo/migrationeditor - no_fix;fbc-sis/codeigniter - 3.0.4;agriya/webshoppack - no_fix;roulette/roulette - no_fix;webwizo/codeigniter-eloquent - no_fix;marcelod/codeistrap - no_fix;jhjjang/sns_login - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |