CVE-2019-13183
Published Jul 7, 2019
Last updated 5 years ago
Overview
- Description
- Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9EF6C49-5066-4252-8356-6109F26CD021" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29211245-B5E7-4D83-BE77-573D8DF19079" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5122F0A6-28F6-4DF5-89E2-850C67729C59" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D9BAA2E-3888-4B81-BB41-6053CBEE20DF" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "637415E5-2EE1-4D2C-BB25-56E59827F060" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CB8737B-762D-4ACA-B172-D36F8A93365A" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36954DAE-127A-4259-8BB6-99B8EF347348" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7.1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A5962B6-2742-46C8-AB55-15E5E6997045" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7.2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE5F5C50-C597-4B0A-B048-5F294C1DFE57" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1D53036-CD08-4A0D-9245-88666EBD6A1B" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta8.1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95A09CC4-B2CC-4D1D-8811-9E4BE5169677" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta8.2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3E94458-6C0B-4E45-BB79-22DB43F80493" } ], "operator": "OR" } ] } ]