Lucene search

K
cvelistMitreCVELIST:CVE-2014-9300
HistoryDec 07, 2014 - 9:00 p.m.

CVE-2014-9300

2014-12-0721:00:00
mitre
www.cve.org
3
cve-2014-9300
csrf
content management interoperability service
alfresco community edition
hijack authentication
unauthorized urls
user credentials

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

61.3%

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

61.3%

Related for CVELIST:CVE-2014-9300