CVE-2013-2754
Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0027 (0.3%)
Percentil: 50.0%
EPSS: 2026-05-06
Afecta
umi-cms:umi.cmsDescripción técnica
Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.
Publicada: 11/3/2014, 19:37:01
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0029.html
- http://osvdb.org/93104
- http://packetstormsecurity.com/files/121564/UMI.CMS-2.9-Cross-Site-Request-Forgery.html
- http://www.exploit-db.com/exploits/25449
- https://www.htbridge.com/advisory/HTB23151
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0029.html
- http://osvdb.org/93104
- http://packetstormsecurity.com/files/121564/UMI.CMS-2.9-Cross-Site-Request-Forgery.html