CVE-2012-1901
FlexCMS < 3.2.1 - Cross-Site Request Forgery via Profile Edit and Page Creation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1901. PoCs published by Ivano Binetti.
AI-analyzed exploit summary This exploit demonstrates multiple CSRF vulnerabilities in FlexCMS 3.2.1, allowing an attacker to change user settings or add new pages when an authenticated user visits a crafted webpage.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hijack the authentication of administrators for requests that add a new page via a request to admin/pages-new-save.
Exploits (1)
This exploit demonstrates multiple CSRF vulnerabilities in FlexCMS 3.2.1, allowing an attacker to change user settings or add new pages when an authenticated user visits a crafted webpage.