Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts.
References
Configurations
History
21 Nov 2024, 01:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/80986 - | |
References | () http://www.exploit-db.com/exploits/18720 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74760 - |
Information
Published : 2012-08-14 21:55
Updated : 2024-11-21 01:42
NVD link : CVE-2012-4325
Mitre link : CVE-2012-4325
CVE.ORG link : CVE-2012-4325
JSON object : View
Products Affected
utopiasoftware
- news_pro
CWE
CWE-352
Cross-Site Request Forgery (CSRF)