Miggo Logo

CVE-2016-4878:
baserCMS Cross Site Request Forgery vulnerability

8.8

CVSS Score

Basic Information

EPSS Score
-
Published
5/17/2022
Updated
7/7/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
baserproject/basercmscomposer<= 3.0.103.0.11

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided vulnerability reports describe a CSRF vulnerability in baserCMS admin functionality but do not specify exact vulnerable functions or file paths. While the CWE-352 classification indicates missing CSRF protections, the advisory texts and references lack technical details about implementation specifics. Without access to the GitHub patch, commit diffs, or code examples from affected versions, there is insufficient evidence to identify specific functions with high confidence. The vulnerability likely stems from admin controller actions lacking CSRF token validation, but exact method names and locations cannot be determined from the available information.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*ross-sit* r*qu*st *or**ry (*SR*) vuln*r**ility in **s*r*MS v*rsion *.*.** *n* **rli*r *llows r*mot* *tt**k*rs to *ij**k t** *ut**nti**tion o* **ministr*tors vi* unsp**i*i** v**tors.

Reasoning

T** provi*** vuln*r**ility r*ports **s*ri** * *SR* vuln*r**ility in **s*r*MS **min *un*tion*lity *ut *o not sp**i*y *x**t vuln*r**l* *un*tions or *il* p*t*s. W*il* t** *W*-*** *l*ssi*i**tion in*i**t*s missin* *SR* prot**tions, t** **visory t*xts *n*