3.5
CVSSv2

CVE-2012-4954

Published: 15/11/2012 Updated: 04/06/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The edit-profile page in Vanilla Forums prior to 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanillaforums vanilla 2.0.17.4

vanillaforums vanilla 2.0.16

vanillaforums vanilla 2.0.15

vanillaforums vanilla 2.0.18

vanillaforums vanilla 2.0.18.1

vanillaforums vanilla 2.0.17.10

vanillaforums vanilla 2.0.7

vanillaforums vanilla 2.0.6

vanillaforums vanilla 2.0.17.5

vanillaforums vanilla 2.0.17.2

vanillaforums vanilla 2.0.14

vanillaforums vanilla 2.0.13

vanillaforums vanilla 2.0.17.9

vanillaforums vanilla 2.0.17.8

vanillaforums vanilla 2.0.5

vanillaforums vanilla 2.0.4

vanillaforums vanilla 2.0.17

vanillaforums vanilla 2.0.9

vanillaforums vanilla 2.0.10

vanillaforums vanilla

vanillaforums vanilla 2.0.18.3

vanillaforums vanilla 2.0.16.1

vanillaforums vanilla 2.0.8

vanillaforums vanilla 2.0.1

vanillaforums vanilla 2.0.0

vanillaforums vanilla forums

vanillaforums vanilla 2.0.17.3

vanillaforums vanilla 2.0.17.1

vanillaforums vanilla 2.0.12

vanillaforums vanilla 2.0.11

vanillaforums vanilla 2.0.17.7

vanillaforums vanilla 2.0.17.6

vanillaforums vanilla 2.0.3

vanillaforums vanilla 2.0.2