CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
joomlajoomla\!
3.2.0
joomlajoomla\!
3.2.1
joomlajoomla\!
3.2.2
joomlajoomla\!
3.2.3
joomlajoomla\!
3.2.4
joomlajoomla\!
3.2.5
joomlajoomla\!
3.3.0
joomlajoomla\!
3.3.1
joomlajoomla\!
3.3.2
joomlajoomla\!
3.3.3
joomlajoomla\!
3.3.4
joomlajoomla\!
3.3.5
joomlajoomla\!
3.4.0
joomlajoomla\!
3.4.0:alpha
joomlajoomla\!
3.4.0:beta1
joomlajoomla\!
3.4.0:beta2
joomlajoomla\!
3.4.0:beta3
joomlajoomla\!
3.4.0:rc1
joomlajoomla\!
3.4.1
joomlajoomla\!
3.4.1:rc1
joomlajoomla\!
3.4.1:rc2
joomlajoomla\!
3.4.2:rc1
𝑥
= Vulnerable software versions