6.8
CVE-2009-4066
- EPSS 0.72%
- Veröffentlicht 24.11.2009 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:58
- Erkennungen
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paul Beaney ≫ Phplist Version 5.x-1.0
Paul Beaney ≫ Phplist Version 5.x-1.1
Paul Beaney ≫ Phplist Version 5.x-1.x Update dev
Paul Beaney ≫ Phplist Version 6.x-1.0
Paul Beaney ≫ Phplist Version 6.x-1.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.72% | 0.491 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
http://drupal.org/node/636398
http://drupal.org/node/636400
http://drupal.org/node/636412
http://osvdb.org/60283
http://secunia.com/advisories/37434
http://www.securityfocus.com/bid/37054
https://exchange.xforce.ibmcloud.com/vulnerabilities/54336