ID |
CVE-2013-2692
|
Sažetak |
Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users. |
Reference |
|
CVSS |
Base: | 6.8 |
Impact: | 6.4 |
Exploitability: | 8.6 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
MEDIUM |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
PARTIAL |
PARTIAL |
|
CVSS vektor |
AV:N/AC:M/Au:N/C:P/I:P/A:P |
Zadnje važnije ažuriranje |
14-05-2014 - 18:04 |
Objavljeno |
13-05-2014 - 14:55 |