CVE-2008-7243
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en la pagina 34 en MODx CMS v0.9.6.1 y v0.9.6.1p1 permite a atacantes remotos secuestrar la autenticación de otros usuarios para las peticiones de modificación de contraseña a través de manager/index.php. NOTA: Debido a la falta de detalles, no queda claro que este relacionado con CVE-2008-5941.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-09-17 CVE Reserved
- 2009-09-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/487696/100/200/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40378 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/27672 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/28840 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Modxcms Search vendor "Modxcms" | Modxcms Search vendor "Modxcms" for product "Modxcms" | 0.9.6.1 Search vendor "Modxcms" for product "Modxcms" and version "0.9.6.1" | - |
Affected
| ||||||
Modxcms Search vendor "Modxcms" | Modxcms Search vendor "Modxcms" for product "Modxcms" | 0.9.6.1 Search vendor "Modxcms" for product "Modxcms" and version "0.9.6.1" | p1 |
Affected
|