Unrated severityNVD Advisory· Published Mar 23, 2015· Updated May 6, 2026
CVE-2015-2680
CVE-2015-2680
Description
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- blog.metalgenix.com/genixcms-v0-0-2-release-security-and-bug-fixes/17nvdPatch
- packetstormsecurity.com/files/130772/GeniXCMS-0.0.1-Cross-Site-Request-Forgery.htmlnvdExploit
- www.exploit-db.com/exploits/36321nvdExploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5234.phpnvdExploit
- blog.metalgenix.com/update-security-fix-and-add-newsletter-module/16nvdVendor Advisory
- osvdb.org/show/osvdb/119391nvd
- www.securityfocus.com/bid/73299nvd
- github.com/semplon/GeniXCMS/commit/698245488343396185b1b49e7482ee5b25541815nvd
- github.com/semplon/GeniXCMS/issues/7nvd
News mentions
0No linked articles in our index yet.