← Back

CVE-2013-2754

nvd nist
Published: Mar 11, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.

Affected (35)

Products: Umi Cms: Umi.cms
1 product
Umi.cms
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Umi Cms
Up to 2.9
Version 2.3.3.9
Version 2.5.0
Version 2.5.2
Version 2.5.3
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.7
Version 2.6.8
Version 2.6
Version 2.7.0
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.8.0.5
Version 2.8.0
Version 2.8.1.2
Version 2.8.1.3
Version 2.8.1
Version 2.8.2
Version 2.8.3
Version 2.8.4.1
Version 2.8.4.2
Version 2.8.4.3
Version 2.8.4.4
Version 2.8.4
Version 2.8.5.1
Version 2.8.5.2
Version 2.8.5.3
Version 2.8.5
Version 2.8.6.1
Version 2.8.6

References (10)

Source: cve@mitre.org
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.