6.8
CVSSv2

CVE-2010-2294

Published: 15/06/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Plume CMS 1.2.4 and possibly earlier allows remote malicious users to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

pxsystem plume-cms