Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-0276
HistoryFeb 13, 2013 - 1:55 a.m.

Cross site request forgery (csrf)

2013-02-1301:55:00
PRIOn knowledge base
www.prio-n.com
10

6.8 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

83.0%

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.