6.8

CVE-2010-3694

Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspecified victims for requests to a preference form.

Data is provided by the National Vulnerability Database (NVD)
HordeHorde Application Framework Version <= 3.3.8
HordeHorde Application Framework Version2.0 Updaterc1
HordeHorde Application Framework Version2.0 Updaterc3
HordeHorde Application Framework Version2.0 Updaterc4
HordeHorde Application Framework Version2.2.6 Updaterc1
HordeHorde Application Framework Version3.0 Updatealpha
HordeHorde Application Framework Version3.0 Updatebeta
HordeHorde Application Framework Version3.0 Updaterc1
HordeHorde Application Framework Version3.0 Updaterc2
HordeHorde Application Framework Version3.0 Updaterc3
HordeHorde Application Framework Version3.0.3 Updaterc1
HordeHorde Application Framework Version3.0.4 Updaterc1
HordeHorde Application Framework Version3.0.4 Updaterc2
HordeHorde Application Framework Version3.0.5 Updaterc1
HordeHorde Application Framework Version3.0.5 Updaterc2
HordeHorde Application Framework Version3.0.6 Updaterc1
HordeHorde Application Framework Version3.1 Updaterc1
HordeHorde Application Framework Version3.1 Updaterc2
HordeHorde Application Framework Version3.1 Updaterc3
HordeHorde Application Framework Version3.1.4 Updaterc1
HordeHorde Application Framework Version3.2 Updatealpha
HordeHorde Application Framework Version3.2 Updaterc1
HordeHorde Application Framework Version3.2 Updaterc2
HordeHorde Application Framework Version3.2 Updaterc3
HordeHorde Application Framework Version3.2 Updaterc4
HordeHorde Application Framework Version3.3 Updaterc1
HordeHorde Application Framework Version3.3.4 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.355
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.