6.8
CVSSv2

CVE-2012-2275

Published: 15/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and previous versions allow remote malicious users to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to lib/usermanagement/userInfo.php.

Vulnerable Product Search on Vulmon Subscribe to Product

teamst testlink 1.8

teamst testlink 1.7.4

teamst testlink 1.8.1

teamst testlink 1.7.3

teamst testlink 1.8.0

teamst testlink 1.8.2

teamst testlink 1.8.4

teamst testlink

teamst testlink 1.7.2

teamst testlink 1.8.3

teamst testlink 1.7.0

teamst testlink 1.7.1

teamst testlink 1.7

Exploits

Advisory ID: HTB23088 Product: TestLink Vendor: teamstorg Vulnerable Version(s): 193 and probably prior Tested Version: 193 Vendor Notification: April 18, 2012 Public Disclosure: September 5, 2012 Vulnerability Type: Cross-Site Request Forgery [CWE-352] CVE Reference: CVE-2012-2275 CVSSv2 Base Score: 51 (AV:N/AC:H/Au:N/C:P/I:P/A:P) Solution ...
TestLink version 193 suffers from a cross site request forgery vulnerability ...