6.8

CVE-2010-5088

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silverstripe ≫ Silverstripe Version 2.3.0
Silverstripe ≫ Silverstripe Version 2.3.0 Update rc1
Silverstripe ≫ Silverstripe Version 2.3.0 Update rc2
Silverstripe ≫ Silverstripe Version 2.3.0 Update rc3
Silverstripe ≫ Silverstripe Version 2.3.1
Silverstripe ≫ Silverstripe Version 2.3.1 Update rc1
Silverstripe ≫ Silverstripe Version 2.3.1 Update rc2
Silverstripe ≫ Silverstripe Version 2.3.2
Silverstripe ≫ Silverstripe Version 2.3.3
Silverstripe ≫ Silverstripe Version 2.3.4
Silverstripe ≫ Silverstripe Version 2.3.5
Silverstripe ≫ Silverstripe Version 2.3.6
Silverstripe ≫ Silverstripe Version 2.3.7
Silverstripe ≫ Silverstripe Version 2.3.8
Silverstripe ≫ Silverstripe Version 2.4.0
Silverstripe ≫ Silverstripe Version 2.4.1
Silverstripe ≫ Silverstripe Version 2.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.587
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://www.openwall.com/lists/oss-security/2012/04/30/3
http://www.openwall.com/lists/oss-security/2011/01/03/12
http://www.openwall.com/lists/oss-security/2012/04/30/1
http://www.openwall.com/lists/oss-security/2012/05/01/3
http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.9
http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.3
http://holisticinfosec.org/content/view/157/45/
http://open.silverstripe.org/changeset/113275
Patch
http://open.silverstripe.org/changeset/113282
Patch
http://secunia.com/advisories/41717
Vendor Advisory
http://www.osvdb.org/69113
http://www.securityfocus.com/bid/44768
https://exchange.xforce.ibmcloud.com/vulnerabilities/63156