Vulnerability CVE-2013-7251


Published: 2014-01-02   Modified: 2014-01-03

Description:
Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Projectforge -> Projectforge 

 References:
http://www.projectforge.org/pf-en/News
http://www.securityfocus.com/bid/64632
https://github.com/micromata/projectforge-webapp/commit/422de35e3c3141e418a73bfb39b430d5fd74077e
https://www.projectforge.org/jira/browse/PF-485

Copyright 2024, cxsecurity.com

 

Back to Top