114 lines
3.1 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2009-3248",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-09-18T20:30:00.250",
"lastModified": "2017-09-19T01:29:31.577",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php."
},
{
"lang": "es",
"value": "Vulnerabilidad de falsificaci\u00f3n de petici\u00f3n en sitios cruzados (CSRF) en el m\u00f3dulo RSS de vtiger CRM v5.0.4, permite a atacantes remotos secuestrar la autenticaci\u00f3n de los usuarios Admin para solicitudes que modifican el sistema de fuentes de noticias a trav\u00e9s del par\u00e1metro rssurl en una acci\u00f3n Save -guardar- en index.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vtiger:vtiger_crm:5.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "84AE51A9-59AF-47F9-8AFC-5219505FD170"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=125060676515670&w=2",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.exploit-db.com/exploits/9450",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/36062",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.ush.it/2009/08/18/vtiger-crm-504-multiple-vulnerabilities/",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.ush.it/team/ush/hack-vtigercrm_504/vtigercrm_504.txt",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.vupen.com/english/advisories/2009/2319",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}