6.8
CVSSv2

CVE-2013-7209

Published: 30/12/2013 Updated: 31/12/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote malicious users to hijack the authentication of administrators for requests that change the user group permissions of arbitrary users via a groupsSave action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jforum jforum -

Exploits

source: wwwsecurityfocuscom/bid/64540/info JForum is prone to a cross-site request-forgery vulnerability because the application does not properly validate HTTP requests Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected application Other attacks are also possible ...
JForum suffers from a cross site request forgery vulnerability ...