VulnerabilityModified
CVE-2009-1455
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an arbitrary password or have other unspecified impact.
MEDIUM 6.8EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an arbitrary password or have other unspecified impact.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- andrew simpson/webcollab
- Source
- cve@mitre.org
References
- http://holisticinfosec.org/content/view/108/45/Patch
- http://secunia.com/advisories/34568Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=676245&group_id=75945Patch
- http://www.osvdb.org/53781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49940
- http://holisticinfosec.org/content/view/108/45/Patch
- http://secunia.com/advisories/34568Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=676245&group_id=75945Patch
- http://www.osvdb.org/53781
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49940
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.