We build. You grow.

Get best community software here

Start a social network, a fan-site, an education project with oxwall - free opensource community software

Vulnerability on Oxwall CMS ?!! | Forum

Walter DAVIN
Walter DAVIN May 25 '17
Is Oxwall corrected for this problem?

« The vulnerability exists due to failure in the "/admin/pages/maintenance" script to properly verify the source of the HTTP request. A remote attacker can trick a logged-in administrator to visit a page with CSRF exploit and put the entire website under maintenance. Additionally, the attacker is able to inject arbitrary HTML and JavaScript code into maintenance message and execute it in browsers of any website visitor. Successful exploitation of this vulnerability may allow an attacker to steal other users ?? cookies, spread malware to website visitors, and even obtain full control over vulnerable website.  »

http://www.securiteam.com/securitynews/5YP382KHQG.html
Senior Developer Leader
Senior Developer May 25 '17

Hi Walter DAVIN!


In the provided url it says:


Immune Systems: 
 * Oxwall after 1.8 


The Current Oxwall Version is 1.8.4



If you already have Oxwall 1.8 or above then you are safe.


Senior Developer

Walter DAVIN
Walter DAVIN May 27 '17
Ok thanks !
Walter DAVIN
Walter DAVIN Jul 14 '17
The administrators left? !!! Spam against Oxwall is average