CVE-2011-1954

Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) comments.php, or (4) perfil.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
VendorProductVersion
postrevpost_revolution
𝑥
≤ 0.8.0c-2
postrevpost_revolution
0.6.2:beta
postrevpost_revolution
0.6.3:beta
postrevpost_revolution
0.6.4
postrevpost_revolution
0.6.5
postrevpost_revolution
0.6.6
postrevpost_revolution
0.7.0:rc1
postrevpost_revolution
0.7.0:rc2
postrevpost_revolution
0.7.0:rc3
postrevpost_revolution
0.7.0:rc4
postrevpost_revolution
0.8.0:alpha
postrevpost_revolution
0.8.0b:b
postrevpost_revolution
0.8.0c:c
𝑥
= Vulnerable software versions