6.8
CVSSv2

CVE-2013-2628

Published: 21/12/2013 Updated: 23/12/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly prior to 1.5 Stable, allow remote malicious users to hijack the authentication of administrators for unspecified requests, related to the lack of an anti-CSRF token.

Vulnerable Product Search on Vulmon Subscribe to Product

idleman leed

Exploits

Leed suffers from authentication bypass, cross site request forgery, and remote SQL injection vulnerabilities ...