Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4729

Опубликовано: 08 фев. 2011
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zikula:zikula_application_framework:*:*:*:*:*:*:*:*
Версия до 1.2.2 (включая)
cpe:2.3:a:zikula:zikula_application_framework:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:zikula:zikula_application_framework:1.2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00182
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
больше 3 лет назад

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.

EPSS

Процентиль: 40%
0.00182
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352