Description
Episerver CMS is a ASP.NET web content management system and digital marketing suite.
Ektron CMS 9.20 SP2 (and older versions) allows remote attackers to access administrative pages such as (/WorkArea/activateuser.aspx) without authentication by faking the Referer HTTP header.
Remediation
Upgrade to the latest version of Ektorn CMS. This vulnerability was patched with EKTR-508 (Security enhancement for re-enabling a user).
References
Related Vulnerabilities
Joomla! Core Security Bypass (1.7.0 - 3.9.22)
WordPress Plugin Content Aware Sidebars-Unlimited Widget Areas Security Bypass (3.8)
WordPress Plugin Floating Cart for WooCommerce Security Bypass (1.2.2)
Security vulnerability in MySQL/MariaDB sql/password.c
WordPress Plugin Login as User or Customer Security Bypass (1.7)