6.8
CVSSv2

CVE-2015-5534

Published: 02/11/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall prior to 1.8 allow remote malicious users to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2) conduct cross-site scripting (XSS) attacks via the maintenance_text parameter to admin/pages/maintenance.

Vulnerable Product Search on Vulmon Subscribe to Product

oxwall oxwall

Exploits

Advisory ID: HTB23266 Product: Oxwall Vendor: wwwoxwallorg Vulnerable Version(s): 174 and probably prior Tested Version: 174 Advisory Publication: July 1, 2015 [without technical details] Vendor Notification: July 1, 2015 Vendor Patch: September 8, 2015 Public Disclosure: October 22, 2015 Vulnerability Type: Cross-Site Request For ...
Oxwall version 174 suffers from a cross site request forgery vulnerability ...