CVE-2015-5397

EUVD-2015-5353
Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
joomlajoomla\!
3.2.0
joomlajoomla\!
3.2.1
joomlajoomla\!
3.2.2
joomlajoomla\!
3.2.3
joomlajoomla\!
3.2.4
joomlajoomla\!
3.2.5
joomlajoomla\!
3.3.0
joomlajoomla\!
3.3.1
joomlajoomla\!
3.3.2
joomlajoomla\!
3.3.3
joomlajoomla\!
3.3.4
joomlajoomla\!
3.3.5
joomlajoomla\!
3.4.0
joomlajoomla\!
3.4.0:alpha
joomlajoomla\!
3.4.0:beta1
joomlajoomla\!
3.4.0:beta2
joomlajoomla\!
3.4.0:beta3
joomlajoomla\!
3.4.0:rc1
joomlajoomla\!
3.4.1
joomlajoomla\!
3.4.1:rc1
joomlajoomla\!
3.4.1:rc2
joomlajoomla\!
3.4.2:rc1
𝑥
= Vulnerable software versions