6.8
CVSSv2

CVE-2009-4898

Published: 07/09/2010 Updated: 12/11/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in TWiki prior to 4.3.2 allows remote malicious users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.

Vulnerable Product Search on Vulmon Subscribe to Product

twiki twiki 4.0.5

twiki twiki 4.0.4

twiki twiki 4.0.3

twiki twiki 4.0.2

twiki twiki 4.2.4

twiki twiki 4.1.2

twiki twiki

twiki twiki 4.1.0

twiki twiki 4.0.1

twiki twiki 4.2.3

twiki twiki 4.2.2

twiki twiki 4.2.1

twiki twiki 4.2.0

twiki twiki 4.3.0

twiki twiki 4.1.1

twiki twiki 4.0.0