LOW · 3.5

CVE-2012-0990

Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify accou...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
DclassifiedsDclassifieds0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0990?

CVE-2012-0990 is a vulnerability with a CVSS score of 3.5 (LOW). Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify accou...

How severe is CVE-2012-0990?

CVE-2012-0990 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0990?

Check the references section above for vendor advisories and patch information. Affected products include: Dclassifieds Dclassifieds.