Описание
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | not-affected | 1.2.7-1 |
| hardy | DNE | |
| karmic | ignored | end of life |
| lucid | released | 1.2.4-1ubuntu0.2 |
| maverick | released | 1.2.5-2ubuntu0.1 |
| natty | not-affected | 1.2.7-1 |
| upstream | released | 1.2.7, 1.3.4 |
Показывать по
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before ...
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
EPSS
5.8 Medium
CVSS2