bloofoxCMS
cpe:2.3:a:bloofox:bloofoxcms:*:*:*:*:*:*:*, +1 more
- <= 0.5.2.1
A cross-site request forgery (CSRF) vulnerability has been identified in bloofoxCMS version 0.5.2.1. This vulnerability allows attackers to perform administrative actions by deceiving logged-in users into visiting malicious websites. Exploitation involves crafting hidden forms that target the admin user creation endpoint, enabling the addition of new administrative accounts with arbitrary credentials, all without explicit user consent.
Exploitation of this vulnerability allows for unauthorized administrative access through the creation of new admin accounts.
To reproduce this vulnerability, a logged-in admin user must be tricked into visiting a crafted webpage. This page should contain a script that automatically submits a form to the admin user creation endpoint, including the desired username and password details. Once the form is submitted, a new admin account will be created with the specified credentials.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.