Vulnerability Description
Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers can forge POST requests to the /admin/adduser endpoint with parameters like username, password, email, and level to create root-level user accounts without user consent.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5134.php
- https://www.exploit-db.com/exploits/24627
- https://www.vulncheck.com/advisories/qool-cms-rc2-cross-site-request-forgery-via
FAQ
What is CVE-2013-20005?
CVE-2013-20005 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious web pages. Attackers ca...
How severe is CVE-2013-20005?
CVE-2013-20005 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-20005?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.