Show plain JSON{"id": "CVE-2012-1498", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2012-03-19T19:55:04.360", "references": [{"url": "http://ivanobinetti.blogspot.com/2012/02/webfoliocms-114-csrf-add-adminmodify.html", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/79658", "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.org/files/110294/WebfolioCMS-1.1.4-Cross-Site-Request-Forgery.html", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/48190", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.exploit-db.com/exploits/18536", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/52218", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73575", "source": "cve@mitre.org"}, {"url": "http://ivanobinetti.blogspot.com/2012/02/webfoliocms-114-csrf-add-adminmodify.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/79658", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://packetstormsecurity.org/files/110294/WebfolioCMS-1.1.4-Cross-Site-Request-Forgery.html", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/48190", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.exploit-db.com/exploits/18536", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/52218", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73575", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-352"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via an add action to admin/users/add or (2) modify a web page via a save action to admin/pages/edit/web_page_name."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de falsificaci\u00f3n de petici\u00f3n en sitios cruzados (CSRF) en Webfolio CMS 1.1.4 y anteriores permiten a atacantes remotos secuestrar la autenticaci\u00f3n de administradores para peticiones que (1) a\u00f1aden un admistrador a trav\u00e9s de una acci\u00f3n \"add\" de admin/users/add o (2) modifican una p\u00e1gina web a trav\u00e9s de una acci\u00f3n \"save\" de admin/pages/edit/web_page_name."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9A2BDD5-3EEC-4211-96C0-0CC41C26D897"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.3:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FC9F75D-0141-44DA-9CFF-B4DB0B8254A4"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.4:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "616A7502-918E-4CCE-A889-2FF81D832E0B"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.5:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "011300FC-3C6E-46EE-9F04-ECBF3771625C"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.6:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1FA1C0A-1271-48FF-98B2-14B1186E0DEB"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.7:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82DE22C4-0788-46DD-96EA-3E6E6511CCCB"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.8:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "449CE159-5743-4ED2-8CEF-8AAE60524402"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.0.9:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6505F0D3-CD0D-4F77-9DE8-0694D627613A"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.1.0:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AD2DB12-1738-464B-BB3E-191A36F0F96F"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.1.1:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01696D3C-C044-487B-86AB-10BFB195097F"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.1.2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FF2FA4B-1264-4BB6-BD22-8E9B7159CA90"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.1.3:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFF34987-9712-4BC7-9E4F-749A961DD5EA"}, {"criteria": "cpe:2.3:a:nikola_posa:webfoliocms1.1.4:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2F5B098-BB27-4953-B7E6-404C0318583C"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}