6.8
CVSSv2

CVE-2014-3854

Published: 07/08/2014 Updated: 07/08/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote malicious users to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pyplate pyplate 0.08

Exploits

source: wwwsecurityfocuscom/bid/67610/info Pyplate is prone to a cross-site request-forgery vulnerability Exploiting this issue may allow a remote attacker to perform certain unauthorized actions This may lead to further attacks Pyplate 008 Beta is vulnerable; other versions may also be affected <html> <body> &lt ...