Lucene search

K
nvd[email protected]NVD:CVE-2015-3624
HistoryJun 09, 2015 - 2:59 p.m.

CVE-2015-3624

2015-06-0914:59:03
CWE-352
web.nvd.nist.gov
2

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.012

Percentile

85.4%

Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action.

Affected configurations

Nvd
Node
ektronektron_content_management_systemRange9.1sp1
VendorProductVersionCPE
ektronektron_content_management_system*cpe:2.3:a:ektron:ektron_content_management_system:*:sp1:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.012

Percentile

85.4%