Executive brief
CMSsite is a content management system used to build and manage websites. A security flaw allows an attacker to trick a logged-in administrator into unknowingly performing actions like creating, modifying, or deleting user accounts. This could lead to an unauthorized takeover of the website's management functions if an administrator visits a malicious link while logged in.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in CMSsite 1.0 due to a lack of anti-CSRF tokens in administrative forms. The vulnerability is located in the 'admin/users.php' endpoint. An unauthenticated remote attacker can craft a malicious HTML page or form that, when visited by an authenticated administrator, triggers a POST request to perform actions such as adding a new user (source=add_user), editing existing users (source=edit_user), or deleting accounts (del=1). This can result in unauthorized administrative account creation or modification. The software is currently archived on GitHub and no official patch has been released.
Affected products
- VictorAlagwu CMSsite 1.0
Timeline
- 2019-03-01: disclosed: Vulnerability discovered by Mr Winst0n
- 2019-03-04: other: Exploit published on Exploit-DB
- 2022-03-06: other: GitHub repository archived by owner
- 2026-04-05: advisory: CVE published and NVD entry created