Administrative password reset in Pagekit CMS - CVE-2017-5594

 

Administrative password reset in Pagekit CMS - CVE-2017-5594

Published: January 25, 2017 / Updated: January 25, 2017


Vulnerability identifier: #VU5378
CSH Severity: High
CVSS v4 BT: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID: CVE-2017-5594
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain administrative access to vulnerable website.

The vulnerability exists due to incorrect validation of user-supplied data during password reset process, when the debug toolbar is enabled. A remote attacker can send a specially crafted HTTP request and reset administrator’s password.

Successful exploitation of the vulnerability may allow an attacker to gain full access to vulnerable website.


Affected software

Pagekit CMS

How to mitigate CVE-2017-5594

Update to version 1.0.11.


External References

Related Security Bulletins