PT-2010-5006 · Horde · Horde Application Framework

Publicado

2010-11-09

·

Atualizado

2011-07-12

·

CVE-2010-3694

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Horde Application Framework versions prior to 3.3.9
Description A cross-site request forgery issue exists, allowing remote attackers to hijack the authentication of victims for requests to a preference form.
Recommendations For versions prior to 3.3.9, update to version 3.3.9 or later to resolve the issue.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3694
DSA-2278-1

Produtos afetados

Horde Application Framework