CVE-2013-5316 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 2.27% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-08-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ritecms | ritecms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RiteCMS 1.0.0 - Multiple Vulnerabilities | 2013-08-03 |
References
- http://packetstormsecurity.com/files/122663/Rite-CMS-1.0.0-Cross-Site-Request-Forgery-Cross-Site-Scripting.html
- http://www.exploit-db.com/exploits/27315
- http://www.securityfocus.com/bid/61587
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86193
- http://packetstormsecurity.com/files/122663/Rite-CMS-1.0.0-Cross-Site-Request-Forgery-Cross-Site-Scripting.html
- http://www.exploit-db.com/exploits/27315
- http://www.securityfocus.com/bid/61587
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86193
→ the Explorer · watch your stack · NVD