Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action.
oryginał ENAV:N/AC:M/Au:N/C:N/I:P/A:PEktron Content Management System
APPEktron≤ 9.1
Powiązane podatności
Ektron CMS: odczyt plików i bypass autoryzacji przez XSLT
RCE w Ektron CMS poprzez złośliwe dane XSL (XslCompiledTransform)
Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.1...
Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0...
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parse...