6.8
CVSSv2

CVE-2013-7204

Published: 17/01/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote malicious users to hijack the authentication of administrators for requests that add arbitrary users.

Vulnerable Product Search on Vulmon Subscribe to Product

conceptronic cipcamptiwl_1.0_firmware 21.37.2.49

conceptronic cipcamptiwl 1.0

Exploits

**General Details** Affected Product: Conceptronic camera CIPCAMPTIWL Tested Firmware: 2137249 Tested Web UI Firmware: 061418 Assigned CVE: CVE-2013-7204 CVSSv2 Base Score: 58 (AV:N/AC:M/AU:N/C:P/I:P/A:N) Vulnerability Type: Cross-Site Request Forgery [CWE-352] Solution Status: Not Fixed Vendor Notification Timeline: - 23/12/2013: Conta ...
Conceptronic camera CIPCAMPTIWL with firmware 2137249 suffers from a cross site request forgery vulnerability ...