CVE-2017-16244
HIGHOctoberCMS < 1.0.427 - Cross-Site Request Forgery via _handler Postback Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16244. PoCs published by Zain Sabahat.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in OctoberCMS 1.0.426, allowing an attacker to bypass CSRF protections by using the '_handler' parameter to take over an admin account.
Description
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in OctoberCMS 1.0.426, allowing an attacker to bypass CSRF protections by using the '_handler' parameter to take over an admin account.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H