VDB
Sign up
MEDIUM5.3

GHSA-2m9r-pm7q-wr6f

GeniXCMS denial of service (account blockage)

Quick fix

GHSA-2m9r-pm7q-wr6f — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.1.0

Details

GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.1.0
Fixcomposer require genix/cms:^1.1.0

References