Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:29590
HistoryJul 15, 2013 - 12:00 a.m.

[Full-disclosure] Magnolia CMS multiple access control vulnerabilities

2013-07-1500:00:00
vulners.com
59

Subject:

Multiple access control vulnerabilities in Magnolia CMS, Community and
Enterprise editions

CVE ID:

CVE-2013-4621

Summary:

A non-admin user (such as default users eric / peter) can access and
execute multiple administrative functionalities of the CMS by
accessing directly the specific URLs.

Product:

Magnolia CMS

Vendor:

Magnolia International Ltd.

Affected versions:

Magnolia CMS <= 4.5.8
Tested on: 4.5.8, 4.5.7 and 4.5.3, both Community and Enterprise editions

Not-affected version:

Magnolia CMS 4.5.9

Product information:

Magnolia CMS is an open-source Web Content Management System that
focuses on providing an intuitive user experience in an
enterprise-scale system.

Vulnerability details:

The following functionalities can be accessed and executed by a
non-admin user based on the URL:

Vendor contact log:

2013-04-25: Contacting vendor through [email protected]
2013-04-29: Vendor acknowledges the receipt of the advisory
2013-04-29: Vendor confirms the vulnerability
2013-06-03: Vendor releases version 4.5.9 which fixes the vulnerability

Credits:

This vulnerability was discovered by Adrian Furtuna
http://pentest-tools.com

Solution:

Upgrade to the latest version of Magnolia CMS

Related for SECURITYVULNS:DOC:29590