CVE-2013-7352
02.04.2014, 18:55
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.
Vendor | Product | Version |
---|---|---|
b2evolution | b2evolution | 𝑥 ≤ 4.1.6 |
b2evolution | b2evolution | 4.1.0 |
b2evolution | b2evolution | 4.1.1 |
b2evolution | b2evolution | 4.1.2 |
b2evolution | b2evolution | 4.1.3 |
b2evolution | b2evolution | 4.1.4 |
b2evolution | b2evolution | 4.1.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References