Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opsview | Opsview | < 4.4.1 |
| Opsview | Opsview Core | < 20130522 |
Related Weaknesses (CWE)
References
- http://docs.opsview.com/doku.php?id=opsview-core:changes#opsview_core_20130822Release Notes
- http://docs.opsview.com/doku.php?id=opsview4.4:changes#fixesBroken Link
- http://docs.opsview.com/doku.php?id=opsview-core:changes#opsview_core_20130822Release Notes
- http://docs.opsview.com/doku.php?id=opsview4.4:changes#fixesBroken Link
FAQ
What is CVE-2013-3935?
CVE-2013-3935 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change...
How severe is CVE-2013-3935?
CVE-2013-3935 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3935?
Check the references section above for vendor advisories and patch information. Affected products include: Opsview Opsview, Opsview Opsview Core.