CVE Vulnerabilities

CVE-2008-3203

Improper Authentication

Published: Jul 17, 2008 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Auracms Auracms 2.2 (including) 2.2 (including)
Auracms Auracms 2.2.1 (including) 2.2.1 (including)
Auracms Auracms 2.2.2 (including) 2.2.2 (including)

Potential Mitigations

References