Lucene search

K
cvelistMitreCVELIST:CVE-2008-0563
HistoryFeb 04, 2008 - 11:00 p.m.

CVE-2008-0563

2008-02-0423:00:00
mitre
www.cve.org
2
cross-site request forgery
userlocalserviceimpl.java
liferay portal 4.3.6
remote attackers
forgot password
user-agent http header

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

46.9%

Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

46.9%

Related for CVELIST:CVE-2008-0563