SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-5090

GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modify or delete data via a request to (1) mod_rewrite.php, (2) comment_write_ok.php, (3) poll/index.php, (4)…

MEDIUM 6.4EPSS 1.30%

Does this matter?

Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.

Description

GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modify or delete data via a request to (1) mod_rewrite.php, (2) comment_write_ok.php, (3) poll/index.php, (4) update/index.php, (5) trackback.php, or (6) an arbitrary poll.php script under theme/.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
1.30% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
grboard/grboard
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.