CVE-2012-1900
Published Oct 22, 2012
Last updated 7 years ago
Overview
- Description
- Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:razorcms:razorcms:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4876FEF-BDCB-418C-A924-C679A538D155", "versionEndIncluding": "1.2.1" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D9EDF45-CA3B-44B8-A87E-99083223007C" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.2:rc:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DAF153BB-A565-4EF8-AD68-2340EA5348BD" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.2:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23E03AD0-3EA0-4ECE-85D5-564B55FC2D00" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "618CC69A-C6DE-4A12-85D5-FCBE628B3288" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "031CFBEB-690A-4B7B-9C1A-9429EA3C7FFA" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA6DD600-E055-4FD8-B78C-B380B0027702" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A9BB13B-9AA3-41C0-B14B-CD8B38A1D020" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:rc:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9B41F7A-CF2D-4C34-B57B-AD909FCDE9F9" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.3:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5B19BB3-8D38-4D4A-928E-75A45A63D6E6" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A846A00-D64E-464E-BA76-8BB1F2783BDE" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E2C9175-F4AD-40ED-8D56-7132FA5E9B59" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FF15EC0-9537-4A0A-AE25-579A5199E4F5" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF9E41CF-D2C4-4712-9CD4-6F8473767D81" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.0:rc:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02DBB072-813A-4FFA-BA55-1570E4304E54" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5306443-AEE9-4831-9DFE-07AF1AF791E1" }, { "criteria": "cpe:2.3:a:razorcms:razorcms:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0E90791-6EA7-4BE5-9D0B-63A2746660DF" } ], "operator": "OR" } ] } ]