6.8

CVE-2012-1297

Exploit
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ContaoContao Cms Version <= 2.11.0
   ContaoContao Cms Version <= 2.11.0
ContaoContao Cms Version2.0
   ContaoContao Cms Version2.0
ContaoContao Cms Version2.0 Updatebeta-rc2
   ContaoContao Cms Version2.0 Updatebeta-rc2
ContaoContao Cms Version2.0 Updatebeta-rc3
   ContaoContao Cms Version2.0 Updatebeta-rc3
ContaoContao Cms Version2.1.0
   ContaoContao Cms Version2.1.0
ContaoContao Cms Version2.1.1
   ContaoContao Cms Version2.1.1
ContaoContao Cms Version2.1.2
   ContaoContao Cms Version2.1.2
ContaoContao Cms Version2.1.3
   ContaoContao Cms Version2.1.3
ContaoContao Cms Version2.1.4
   ContaoContao Cms Version2.1.4
ContaoContao Cms Version2.1.5
   ContaoContao Cms Version2.1.5
ContaoContao Cms Version2.1.6
   ContaoContao Cms Version2.1.6
ContaoContao Cms Version2.1.7
   ContaoContao Cms Version2.1.7
ContaoContao Cms Version2.1.8
   ContaoContao Cms Version2.1.8
ContaoContao Cms Version2.1.9
   ContaoContao Cms Version2.1.9
ContaoContao Cms Version2.1.10
   ContaoContao Cms Version2.1.10
ContaoContao Cms Version2.1.11
   ContaoContao Cms Version2.1.11
ContaoContao Cms Version2.1.12
   ContaoContao Cms Version2.1.12
ContaoContao Cms Version2.1.13
   ContaoContao Cms Version2.1.13
ContaoContao Cms Version2.1.14
   ContaoContao Cms Version2.1.14
ContaoContao Cms Version2.1.15
   ContaoContao Cms Version2.1.15
ContaoContao Cms Version2.1.16
   ContaoContao Cms Version2.1.16
ContaoContao Cms Version2.1.17
   ContaoContao Cms Version2.1.17
ContaoContao Cms Version2.1.18
   ContaoContao Cms Version2.1.18
ContaoContao Cms Version2.1.19
   ContaoContao Cms Version2.1.19
ContaoContao Cms Version2.1.20
   ContaoContao Cms Version2.1.20
ContaoContao Cms Version2.2.0
   ContaoContao Cms Version2.2.0
ContaoContao Cms Version2.2.1
   ContaoContao Cms Version2.2.1
ContaoContao Cms Version2.2.2
   ContaoContao Cms Version2.2.2
ContaoContao Cms Version2.2.3
   ContaoContao Cms Version2.2.3
ContaoContao Cms Version2.2.4
   ContaoContao Cms Version2.2.4
ContaoContao Cms Version2.2.5
   ContaoContao Cms Version2.2.5
ContaoContao Cms Version2.2.6
   ContaoContao Cms Version2.2.6
ContaoContao Cms Version2.2.7
   ContaoContao Cms Version2.2.7
ContaoContao Cms Version2.2.8
   ContaoContao Cms Version2.2.8
ContaoContao Cms Version2.2.9
   ContaoContao Cms Version2.2.9
ContaoContao Cms Version2.2.10
   ContaoContao Cms Version2.2.10
ContaoContao Cms Version2.2.11
   ContaoContao Cms Version2.2.11
ContaoContao Cms Version2.2.12
   ContaoContao Cms Version2.2.12
ContaoContao Cms Version2.3.0
   ContaoContao Cms Version2.3.0
ContaoContao Cms Version2.3.1
   ContaoContao Cms Version2.3.1
ContaoContao Cms Version2.3.2
   ContaoContao Cms Version2.3.2
ContaoContao Cms Version2.3.3
   ContaoContao Cms Version2.3.3
ContaoContao Cms Version2.3.4
   ContaoContao Cms Version2.3.4
ContaoContao Cms Version2.4.0
   ContaoContao Cms Version2.4.0
ContaoContao Cms Version2.4.0 Updatebeta
   ContaoContao Cms Version2.4.0 Updatebeta
ContaoContao Cms Version2.4.1
   ContaoContao Cms Version2.4.1
ContaoContao Cms Version2.4.2
   ContaoContao Cms Version2.4.2
ContaoContao Cms Version2.4.3
   ContaoContao Cms Version2.4.3
ContaoContao Cms Version2.4.4
   ContaoContao Cms Version2.4.4
ContaoContao Cms Version2.4.5
   ContaoContao Cms Version2.4.5
ContaoContao Cms Version2.4.6
   ContaoContao Cms Version2.4.6
ContaoContao Cms Version2.4.7
   ContaoContao Cms Version2.4.7
ContaoContao Cms Version2.5.0
   ContaoContao Cms Version2.5.0
ContaoContao Cms Version2.5.0 Updatebeta
   ContaoContao Cms Version2.5.0 Updatebeta
ContaoContao Cms Version2.5.0 Updatebeta-rc2
   ContaoContao Cms Version2.5.0 Updatebeta-rc2
ContaoContao Cms Version2.5.1
   ContaoContao Cms Version2.5.1
ContaoContao Cms Version2.5.2
   ContaoContao Cms Version2.5.2
ContaoContao Cms Version2.5.3
   ContaoContao Cms Version2.5.3
ContaoContao Cms Version2.5.4
   ContaoContao Cms Version2.5.4
ContaoContao Cms Version2.5.5
   ContaoContao Cms Version2.5.5
ContaoContao Cms Version2.5.6
   ContaoContao Cms Version2.5.6
ContaoContao Cms Version2.5.7
   ContaoContao Cms Version2.5.7
ContaoContao Cms Version2.5.8
   ContaoContao Cms Version2.5.8
ContaoContao Cms Version2.5.9
   ContaoContao Cms Version2.5.9
ContaoContao Cms Version2.6.0
   ContaoContao Cms Version2.6.0
ContaoContao Cms Version2.6.0 Updatebeta
   ContaoContao Cms Version2.6.0 Updatebeta
ContaoContao Cms Version2.6.0 Updatebeta2
   ContaoContao Cms Version2.6.0 Updatebeta2
ContaoContao Cms Version2.6.1
   ContaoContao Cms Version2.6.1
ContaoContao Cms Version2.6.2
   ContaoContao Cms Version2.6.2
ContaoContao Cms Version2.6.3
   ContaoContao Cms Version2.6.3
ContaoContao Cms Version2.6.4
   ContaoContao Cms Version2.6.4
ContaoContao Cms Version2.6.5
   ContaoContao Cms Version2.6.5
ContaoContao Cms Version2.6.6
   ContaoContao Cms Version2.6.6
ContaoContao Cms Version2.6.7
   ContaoContao Cms Version2.6.7
ContaoContao Cms Version2.6.8
   ContaoContao Cms Version2.6.8
ContaoContao Cms Version2.7.0
   ContaoContao Cms Version2.7.0
ContaoContao Cms Version2.7.0 Updaterc1
   ContaoContao Cms Version2.7.0 Updaterc1
ContaoContao Cms Version2.7.0 Updaterc2
   ContaoContao Cms Version2.7.0 Updaterc2
ContaoContao Cms Version2.7.1
   ContaoContao Cms Version2.7.1
ContaoContao Cms Version2.7.2
   ContaoContao Cms Version2.7.2
ContaoContao Cms Version2.7.3
   ContaoContao Cms Version2.7.3
ContaoContao Cms Version2.7.4
   ContaoContao Cms Version2.7.4
ContaoContao Cms Version2.7.5
   ContaoContao Cms Version2.7.5
ContaoContao Cms Version2.7.6
   ContaoContao Cms Version2.7.6
ContaoContao Cms Version2.7.7
   ContaoContao Cms Version2.7.7
ContaoContao Cms Version2.8.0
   ContaoContao Cms Version2.8.0
ContaoContao Cms Version2.8.0 Updaterc1
   ContaoContao Cms Version2.8.0 Updaterc1
ContaoContao Cms Version2.8.0 Updaterc2
   ContaoContao Cms Version2.8.0 Updaterc2
ContaoContao Cms Version2.8.1
   ContaoContao Cms Version2.8.1
ContaoContao Cms Version2.8.2
   ContaoContao Cms Version2.8.2
ContaoContao Cms Version2.8.3
   ContaoContao Cms Version2.8.3
ContaoContao Cms Version2.8.4
   ContaoContao Cms Version2.8.4
ContaoContao Cms Version2.9.0
   ContaoContao Cms Version2.9.0
ContaoContao Cms Version2.9.0 Updatebeta1
   ContaoContao Cms Version2.9.0 Updatebeta1
ContaoContao Cms Version2.9.0 Updaterc1
   ContaoContao Cms Version2.9.0 Updaterc1
ContaoContao Cms Version2.9.1
   ContaoContao Cms Version2.9.1
ContaoContao Cms Version2.9.2
   ContaoContao Cms Version2.9.2
ContaoContao Cms Version2.9.3
   ContaoContao Cms Version2.9.3
ContaoContao Cms Version2.9.4
   ContaoContao Cms Version2.9.4
ContaoContao Cms Version2.9.5
   ContaoContao Cms Version2.9.5
ContaoContao Cms Version2.10. Updatebeta
   ContaoContao Cms Version2.10. Updatebeta
ContaoContao Cms Version2.10.0
   ContaoContao Cms Version2.10.0
ContaoContao Cms Version2.10.0 Updaterc1
   ContaoContao Cms Version2.10.0 Updaterc1
ContaoContao Cms Version2.10.1
   ContaoContao Cms Version2.10.1
ContaoContao Cms Version2.10.2
   ContaoContao Cms Version2.10.2
ContaoContao Cms Version2.10.3
   ContaoContao Cms Version2.10.3
ContaoContao Cms Version2.10.4
   ContaoContao Cms Version2.10.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.