Vulnerability Description
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Metalgenix | Genixcms | 1.1.7 |
Related Weaknesses (CWE)
References
- https://github.com/J3rryBl4nks/GenixCMS/blob/master/CreateAdminBAC.mdExploitThird Party Advisory
- https://github.com/J3rryBl4nks/GenixCMS/blob/master/CreateAdminBAC.mdExploitThird Party Advisory
FAQ
What is CVE-2020-10057?
CVE-2020-10057 is a vulnerability with a CVSS score of 8.8 (HIGH). GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection ...
How severe is CVE-2020-10057?
CVE-2020-10057 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10057?
Check the references section above for vendor advisories and patch information. Affected products include: Metalgenix Genixcms.