6.8
CVSSv2

CVE-2010-5315

Published: 03/01/2015 Updated: 05/01/2015
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita prior to 3.1 allow remote malicious users to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify credentials via a data array to admin/saveUser.

Vulnerable Product Search on Vulmon Subscribe to Product

chialab \\& channelweb bedita

Exploits

Vulnerability ID: HTB22729 Reference: wwwhtbridgech/advisory/xsrf_csrf_in_beditahtml Product: BEdita Vendor: Chialab & ChannelWeb ( wwwbeditacom/ ) Vulnerable Version: 3012550 "betula" and probably prior versions Vendor Notification: 30 November 2010 Vulnerability Type: CSRF (Cross-Site Request Forgery) Status: Not Fixed ...