CVE-2007-5918 describes a Cross-Site Request Forgery (CSRF) vulnerability in the MS TopSites add-on for PHP-Nuke, specifically within the edit.php component. This flaw allows authenticated attackers to modify arbitrary user accounts or change the SiteTitleName field for any user by manipulating the 'uname' parameter in an edit action. With a CVSS score of 6.0 (medium severity), successful exploitation requires user authentication and medium attack complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and showing no community discussion or media coverage, an exploit is publicly available on ExploitDB, indicating a potential for targeted attacks despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ms_topsites:ms_topsites:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.