CVE-2010-5315
BEdita < 3.0.1.2550 "betula" - Cross-Site Request Forgery via News Categories or Admin User Save
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-5315. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates CSRF and XSS vulnerabilities in BEdita 3.0.1.2550. It includes PoC forms for CSRF-based user modification and XSS via unsanitized input in 'data[label]' and 'searchstring' parameters.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify credentials via a data array to admin/saveUser.
Exploits (1)
The exploit demonstrates CSRF and XSS vulnerabilities in BEdita 3.0.1.2550. It includes PoC forms for CSRF-based user modification and XSS via unsanitized input in 'data[label]' and 'searchstring' parameters.