Kirby cms csrf upload and PHP Script Execution Vulnerability
Kirby cms csrf upload and PHP Script Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Kirby CMS <= 2.1.0
Kirby CMS
Description:
Kirby CMS is a file-based content management system that is flexible, easy to use and easy to install.
KirbyCMS has the Cross-Site Request Forgery Vulnerability in implementation, which allows attackers to upload files with the current user permission. If attackers trick users into browsing the constructed website, this vulnerability allows unauthorized attackers to modify or upload new content and execute arbitrary PHP code on a remote server.
<* Source: annoymous
*>
Suggestion:
Vendor patch:
Kirby
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://getkirby.com/changelog/kirby-2-1-1
This article permanently updates the link address: