PT-2008-6517 · Mvnforum · Mvnforum

Published

2008-12-09

·

Updated

2024-02-14

·

CVE-2008-5400

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions mvnForum versions prior to 1.2.1 GA
Description The issue allows remote attackers to perform various actions as a product administrator, including creating forums, changing account privileges, enabling accounts, or disabling accounts. This is due to multiple cross-site request forgery (CSRF) vulnerabilities.
Recommendations For mvnForum versions prior to 1.2.1 GA, update to version 1.2.1 GA or later to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2008-5400

Affected Products

Mvnforum