4.3
CVSSv2

CVE-2010-3026

Published: 16/08/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote malicious users to hijack the authentication of administrators for requests to admin/users/edit that grant administrative privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

tomaz-muraus open blog 1.2.1

Exploits

Vulnerability ID: HTB22496 Reference: wwwhtbridgech/advisory/xsrf_csrf_in_open_bloghtml Product: Open Blog Vendor: Tomaž Muraus ( wwwopen-bloginfo/ ) Vulnerable Version: 121 and Probably Prior Versions Vendor Notification: 22 July 2010 Vulnerability Type: CSRF (Cross-Site Request Forgery) Status: Not Fixed, Vendor Alerted, A ...