MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/
Published Jan 2, 2014
6.8
MEDIUMCVSS 2.0
EPSS 1.10%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.