peter bassill · operator
$ cve CVE-2012-4902 JSON

CVE-2012-4902 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 69)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the themes_editor parameter in an edit_template action to admin/index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.29% — more likely to be exploited than 69% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2015-05-20
Last modified2026-06-16

Affected (1)

VendorProduct
template cms projecttemplate cms

Public exploits

SourceTitleDate
exploit-dbTemplate CMS 2.1.1 - Multiple Vulnerabilities2012-10-04

References

→ the Explorer  ·  watch your stack  ·  NVD