6.8
CVSSv2

CVE-2013-4562

Published: 13/05/2014 Updated: 14/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The omniauth-facebook gem 1.4.1 prior to 1.5.0 does not properly store the session parameter, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks via the state parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

madeofcode omniauth-facebook 1.4.1