CVE-2012-1414
Plume CMS < 1.2.4 - Cross-Site Request Forgery via News Page Creation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1414. PoCs published by Ivano Binetti.
AI-analyzed exploit summary This is a CSRF exploit for PlumeCMS <= 1.2.4 that allows an attacker to insert and publish news articles by tricking an authenticated admin into visiting a malicious webpage. The exploit submits a form with hidden fields to the target application.
Description
Cross-site request forgery (CSRF) vulnerability in manager/news.php in Plume CMS 1.2.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that create News pages via a publish action.
Exploits (1)
This is a CSRF exploit for PlumeCMS <= 1.2.4 that allows an attacker to insert and publish news articles by tricking an authenticated admin into visiting a malicious webpage. The exploit submits a form with hidden fields to the target application.