XEpan Cross-Site Request Forgery Vulnerability (CVE-2014-8429)
Release date:
Updated on:
Affected Systems:
XEpan <= 1.0.1
XEpan
Description:
Bugtraq id: 71309
CVE (CAN) ID: CVE-2014-8429
XEpan is an open source php cms.
XEpan does not effectively authenticate HTTP requests when creating a new account. unauthenticated remote attackers can entice logged-on administrators to browse malicious webpages and exploit this vulnerability to perform unauthorized operations.
<* Source: High-Tech Bridge Security Research Lab
Link: http://www.securityfocus.com/archive/1/534096
*>
Suggestion:
Vendor patch:
XEpan
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.xepan.org/
This article permanently updates the link address: