CVE-2017-7881

HIGH

Bigtreecms Bigtree Cms < 4.2.17 - CSRF

Title source: rule
STIX 2.1

Description

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.cdxy.me/?p=765

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
bigtreecms/bigtree_cms < 4.2.17
Published Apr 15, 2017
Tracked Since Feb 18, 2026