JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-06-16T21:53:34
Updated: 2024-08-03T04:56:37.891Z
Reserved: 2022-02-28T00:00:00
Link: CVE-2022-26173
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-06-16T22:15:07.940
Modified: 2022-06-28T18:36:56.553
Link: CVE-2022-26173
Redhat
No data.