Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action.
References
| Link | Resource |
|---|---|
| https://github.com/bigtreecms/BigTree-CMS/commit/4b0faa90fa8b9e1776c86db716894dcd7e6b4834 | Exploit Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-08-19 14:10
Updated : 2013-08-20 06:30
NVD link : CVE-2013-5313
Mitre link : CVE-2013-5313
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
bigtreecms
- bigtree_cms


