← Back

CVE-2012-4954

nvd nist
Published: Nov 15, 2012Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

Affected (41)

2 products
Vanilla
Vanilla Forums
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Vanillaforums
Up to 2.0.18.4
Version 2.0.0
Version 2.0.10
Version 2.0.11
Version 2.0.12
Version 2.0.13
Version 2.0.14
Version 2.0.15
Version 2.0.16.1
Version 2.0.16
Version 2.0.17.10
Version 2.0.17.1
Version 2.0.17.2
Version 2.0.17.3
Version 2.0.17.4
Version 2.0.17.5
Version 2.0.17.6
Version 2.0.17.7
Version 2.0.17.8
Version 2.0.17.9
Version 2.0.17
Version 2.0.18.1
Version 2.0.18.3
Version 2.0.18
Version 2.0.18 alpha3
Version 2.0.18 beta1
Version 2.0.18 beta2
Version 2.0.18 beta4
Version 2.0.18 rc1
Version 2.0.18 rc2
Version 2.0.18 rc3
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Up to 2.1

Related CWEs

References (6)

Source: cret@cert.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.