CVE-2011-5074

Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
sitrackersupport_incident_tracker
𝑥
≤ 3.64
sitrackersupport_incident_tracker
3.6
sitrackersupport_incident_tracker
3.21
sitrackersupport_incident_tracker
3.22
sitrackersupport_incident_tracker
3.22pl1:pl1
sitrackersupport_incident_tracker
3.23
sitrackersupport_incident_tracker
3.24
sitrackersupport_incident_tracker
3.24:beta-2
sitrackersupport_incident_tracker
3.30
sitrackersupport_incident_tracker
3.30:beta2
sitrackersupport_incident_tracker
3.31
sitrackersupport_incident_tracker
3.32
sitrackersupport_incident_tracker
3.33
sitrackersupport_incident_tracker
3.35
sitrackersupport_incident_tracker
3.35:beta1
sitrackersupport_incident_tracker
3.36
sitrackersupport_incident_tracker
3.40
sitrackersupport_incident_tracker
3.40:beta1
sitrackersupport_incident_tracker
3.41
sitrackersupport_incident_tracker
3.45
sitrackersupport_incident_tracker
3.45:beta1
sitrackersupport_incident_tracker
3.50
sitrackersupport_incident_tracker
3.50:beta1
sitrackersupport_incident_tracker
3.51
sitrackersupport_incident_tracker
3.60
sitrackersupport_incident_tracker
3.61
sitrackersupport_incident_tracker
3.62
sitrackersupport_incident_tracker
3.63
sitrackersupport_incident_tracker
3.63:beta1
𝑥
= Vulnerable software versions