Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php.
Link | Tags |
---|---|
http://securityreason.com/securityalert/2239 | third party advisory |
http://www.securityfocus.com/archive/1/459827/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32458 | vdb entry |
http://osvdb.org/33712 | vdb entry |