CVE-2013-2628
Published Dec 21, 2013
Last updated 11 years ago
Overview
- Description
- Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to hijack the authentication of administrators for unspecified requests, related to the lack of an anti-CSRF token.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:idleman:leed:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3561C5F2-F58C-4DDE-9899-D7C6E54D76B1", "versionEndIncluding": "1.4" } ], "operator": "OR" } ] } ]