SecBoard
Zurück zur CVE-Übersicht

CVE-2009-2150

MEDIUM(6.8)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Risk Signal Score17/100 — NIEDRIG
  • CVSS 6.8 — Mittel

EPSS-Score

1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

6.8

Technische Schwere

Beschreibung

Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack the authentication of arbitrary users for requests that terminate a session via login/logout.php, and might allow remote attackers to hijack the authentication of certain users via a (2) ADD or (3) DELETE action to enrolments/step2.php.

Referenzen