Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, related to CVE-2013-2559.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-04/0018.html | Exploit |
https://www.htbridge.com/advisory/HTB23148 | Exploit |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:14:53
Updated: 2022-10-03T16:14:53
Reserved: 2022-10-03T00:00:00
Link: CVE-2013-7346
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-03-27T16:55:05.613
Modified: 2020-08-25T15:59:18.950
Link: CVE-2013-7346
JSON object: View
Redhat Information
No data.
CWE