← Back

CVE-2008-3760

nvd nist
Published: Aug 21, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout via a SignOutNow action to people.php.

Affected (10)

Products: Lussumo: Vanilla
1 product
Vanilla
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Lussumo
Up to 1.1.4
Version 0.9.2
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1
Version 1

Timeline

No history available yet.