6.8
CVE-2013-3253
- EPSS 0.25%
- Veröffentlicht 09.08.2013 20:56:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Xhanch – My Twitter <= 2.7.6 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in admin/setting.php in the Xhanch - My Twitter plugin before 2.7.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change unspecified settings.
Mögliche Gegenmaßnahme
Xhanch – My Twitter: Update to version 2.7.7, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Xhanch – My Twitter
Version
* - 2.7.6
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xhanch ≫ My Twitter SwPlatformwordpress Version <= 2.7.6
Xhanch ≫ My Twitter Version2.5.8 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.5.9 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.0 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.1 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.2 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.3 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.4 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.5 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.6 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.7 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.8 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.6.9 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.0 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.1 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.2 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.3 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.4 SwPlatformwordpress
Xhanch ≫ My Twitter Version2.7.5 SwPlatformwordpress
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.