SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1915

Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update…

MEDIUM 6.8EPSS 2.47%

Does this matter?

Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update action to sw/admin_change_password.php or (2) unspecified victims for requests that add a topic or blog entry to sw/add_topic.php. NOTE: vector 2 can be leveraged to bypass the authentication requirements for exploiting vector 1 in CVE-2014-1914.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.47% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
doug poulin/command school student management system
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.