6.8
CVSSv2

CVE-2013-7346

Published: 27/03/2014 Updated: 25/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Symphony CMS prior to 2.3.2 allows remote malicious users to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, related to CVE-2013-2559.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getsymphony symphony

getsymphony symphony 2.0.7

getsymphony symphony 2.1.1

getsymphony symphony 2.0

getsymphony symphony 2.0.3

getsymphony symphony 2.0.4

getsymphony symphony 2.0.5

getsymphony symphony 2.3

getsymphony symphony 2.0.6

getsymphony symphony 2.1.0

Exploits

source: wwwsecurityfocuscom/bid/66536/info Symphony is prone to a cross-site request-forgery vulnerability An attacker can exploit the cross-site request forgery issue to perform unauthorized actions in the context of a logged-in user of the affected application This may aid in other attacks Symphony version 231 and prior are vulne ...