CVE
- Id
- 65260
- CVE No.
- CVE-2013-5313
- Status
- Candidate
- Description
- Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action.
- Phase
- Assigned (20130819)
- Votes
- None (candidate not yet proposed)
- Comments