605
VMScore

CVE-2016-10522

Published: 05/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rails admin project rails admin

Vendor Advisories

Debian Bug report logs - #903855 CVE-2016-10522 Package: ruby-rails-admin; Maintainer for ruby-rails-admin is Debian Ruby Extras Maintainers &lt;pkg-ruby-extras-maintainers@listsaliothdebianorg&gt;; Source for ruby-rails-admin is src:ruby-rails-admin (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; ...