MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting (XSS) attacks via unspecified vectors
Published Oct 9, 2013
6.8
MEDIUMCVSS 2.0
EPSS 1.06%
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected products
No data.
AND
OR
- ≤ 1.0.34
- 1.0.00
- 1.0.01
- 1.0.02
- 1.0.03
- 1.0.04
- 1.0.05
- 1.0.06
- 1.0.07
- 1.0.08
- 1.0.09
- 1.0.10
- 1.0.11
- 1.0.12
- 1.0.13
- 1.0.14
- 1.0.15
- 1.0.16
- 1.0.17
- 1.0.18
- 1.0.19
- 1.0.20
- 1.0.21
- 1.0.21.1
- 1.0.22
- 1.0.23
- 1.0.23.1
- 1.0.23.2
- 1.0.24
- 1.0.25
- 1.0.26
- 1.0.27
- 1.0.28
- 1.0.28.1
- 1.0.28.2
- 1.0.29
- 1.0.30
- 1.0.31
- 1.0.31.1
- 1.0.31.2
- 1.0.31.3
- 1.0.31.4
- 1.0.32
- 1.0.32.1
- 1.0.33
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://osvdb.org/96905 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/47687 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/secunia_research/2013-6 x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/bid/62133 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/96905 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/47687 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/secunia_research/2013-6 | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/bid/62133 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Oct 9, 2013
Updated Sep 16, 2024
Reserved Jan 2, 2013
Link CVE-2013-0736
CISA Vulnrichment
Updated n/a