Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Umi.cms | Umi-cms | * | 2.9 (including) |
Umi.cms | Umi-cms | 2.3.3.9 (including) | 2.3.3.9 (including) |
Umi.cms | Umi-cms | 2.5.0 (including) | 2.5.0 (including) |
Umi.cms | Umi-cms | 2.5.2 (including) | 2.5.2 (including) |
Umi.cms | Umi-cms | 2.5.3 (including) | 2.5.3 (including) |
Umi.cms | Umi-cms | 2.6 (including) | 2.6 (including) |
Umi.cms | Umi-cms | 2.6.1 (including) | 2.6.1 (including) |
Umi.cms | Umi-cms | 2.6.2 (including) | 2.6.2 (including) |
Umi.cms | Umi-cms | 2.6.3 (including) | 2.6.3 (including) |
Umi.cms | Umi-cms | 2.6.4 (including) | 2.6.4 (including) |
Umi.cms | Umi-cms | 2.6.5 (including) | 2.6.5 (including) |
Umi.cms | Umi-cms | 2.6.7 (including) | 2.6.7 (including) |
Umi.cms | Umi-cms | 2.6.8 (including) | 2.6.8 (including) |
Umi.cms | Umi-cms | 2.7.0 (including) | 2.7.0 (including) |
Umi.cms | Umi-cms | 2.7.2 (including) | 2.7.2 (including) |
Umi.cms | Umi-cms | 2.7.3 (including) | 2.7.3 (including) |
Umi.cms | Umi-cms | 2.7.4 (including) | 2.7.4 (including) |
Umi.cms | Umi-cms | 2.8.0 (including) | 2.8.0 (including) |
Umi.cms | Umi-cms | 2.8.0.5 (including) | 2.8.0.5 (including) |
Umi.cms | Umi-cms | 2.8.1 (including) | 2.8.1 (including) |
Umi.cms | Umi-cms | 2.8.1.2 (including) | 2.8.1.2 (including) |
Umi.cms | Umi-cms | 2.8.1.3 (including) | 2.8.1.3 (including) |
Umi.cms | Umi-cms | 2.8.2 (including) | 2.8.2 (including) |
Umi.cms | Umi-cms | 2.8.3 (including) | 2.8.3 (including) |
Umi.cms | Umi-cms | 2.8.4 (including) | 2.8.4 (including) |
Umi.cms | Umi-cms | 2.8.4.1 (including) | 2.8.4.1 (including) |
Umi.cms | Umi-cms | 2.8.4.2 (including) | 2.8.4.2 (including) |
Umi.cms | Umi-cms | 2.8.4.3 (including) | 2.8.4.3 (including) |
Umi.cms | Umi-cms | 2.8.4.4 (including) | 2.8.4.4 (including) |
Umi.cms | Umi-cms | 2.8.5 (including) | 2.8.5 (including) |
Umi.cms | Umi-cms | 2.8.5.1 (including) | 2.8.5.1 (including) |
Umi.cms | Umi-cms | 2.8.5.2 (including) | 2.8.5.2 (including) |
Umi.cms | Umi-cms | 2.8.5.3 (including) | 2.8.5.3 (including) |
Umi.cms | Umi-cms | 2.8.6 (including) | 2.8.6 (including) |
Umi.cms | Umi-cms | 2.8.6.1 (including) | 2.8.6.1 (including) |