6.8
CVSSv2

CVE-2013-5748

Published: 12/05/2014 Updated: 13/05/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk prior to 20130916-001 allows remote malicious users to hijack the authentication of users for requests that add projects via an add_project action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

simplerisk simplerisk

Exploits

1 *Advisory Information* Title: SimpleRisk v20130915-01 CSRF-XSS Account Compromise Advisory ID: RS-2013-0001 Date Published: 2013-09-30 2 *Vulnerability Information* Type: Cross-Site Request Forgery (CSRF) [CWE-352, OWASP-A8], Cross-Site Scripting (XSS) [CWE-79, OWASP-A3] Impact: Full Account Compromise Remotely Exploitable: Yes Locally Expl ...
SimpleRisk version 20130915-01 suffers from cross site request forgery and cross site scripting vulnerabilities ...