{ "id": "CVE-2011-4452", "sourceIdentifier": "cve@mitre.org", "published": "2012-09-05T20:55:01.287", "lastModified": "2012-09-06T13:08:18.160", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete operation, as demonstrated by an {{image}} action." }, { "lang": "es", "value": "Vulnerabilidad de falsificaci\u00f3n de peticiones en sitios cruzados (CSRF) en el componente AdminUsers en WikkaWiki v1.3.1 y v1.3.2 permite a atacantes remotos secuestrar la autenticaci\u00f3n de los administradores de las peticiones que elimina cuentas de usuario arbitrarios a trav\u00e9s de una operaci\u00f3n de eliminaci\u00f3n, como lo demuestra un acci\u00f3n {{imagen }}." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-352" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.1:*:*:*:*:*:*:*", "matchCriteriaId": "63F5FD8C-02BB-4208-AEF8-11797376DA23" }, { "vulnerable": true, "criteria": "cpe:2.3:a:wikkawiki:wikkawiki:1.3.2:*:*:*:*:*:*:*", "matchCriteriaId": "C44D576A-77E7-4E70-9E17-41E96A9A4A2A" } ] } ] } ], "references": [ { "url": "http://wush.net/trac/wikka/changeset/1819", "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ] }, { "url": "http://wush.net/trac/wikka/changeset/1832", "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ] }, { "url": "http://wush.net/trac/wikka/ticket/1097", "source": "cve@mitre.org" }, { "url": "http://wush.net/trac/wikka/ticket/1098", "source": "cve@mitre.org", "tags": [ "Exploit" ] } ] }