6.8

CVE-2008-7243

Exploit
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php.  NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ModxcmsModxcms Version0.9.6.1
ModxcmsModxcms Version0.9.6.1 Updatep1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.454
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://secunia.com/advisories/28840
Vendor Advisory
http://www.securityfocus.com/archive/1/487696/100/200/threaded
http://www.securityfocus.com/bid/27672
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/40378