6.8
CVE-2013-5355
- EPSS 0.64%
- Veröffentlicht 09.12.2013 16:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) create new administrative users via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sharetronix ≫ Sharetronix Version3.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.64% | 0.46 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
http://secunia.com/advisories/53936
http://www.securityfocus.com/bid/64102
http://osvdb.org/100608
http://secunia.com/secunia_research/2013-11