Executive brief
bloofoxCMS, an open-source content management system, is vulnerable to an attack that could allow unauthorized individuals to gain administrative control. By tricking a logged-in administrator into visiting a malicious website, an attacker can silently create a new administrative account with their own credentials. This could lead to a full takeover of the website, allowing the attacker to modify content or access sensitive data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in bloofoxCMS versions 0.5.1.0 through 0.5.2.1 due to a lack of anti-CSRF tokens or validation on administrative endpoints. Specifically, the user creation component at 'admin/index.php?mode=user&action=new' does not verify the intent of the request. A remote attacker can exploit this by hosting a malicious page with a hidden auto-submitting HTML form. If an authenticated administrator visits this page, the browser will execute a POST request to the CMS, creating a new administrative user with attacker-defined credentials. This allows for full privilege escalation and persistent access to the CMS backend.
Affected products
- bloofox bloofoxCMS 0.5.1.0 through 0.5.2.1
Timeline
- 2020-12-18: disclosed: Initial discovery by researcher LiPeiYi
- 2021-02-01: other: Exploit published on Exploit-DB
- 2026-05-16: advisory: NVD/VulnCheck advisory published