← Back

CVE-2014-4333

nvd nist
Published: Jun 19, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

Affected (18)

Products: Boonex: Dolphin
1 product
Dolphin
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Boonex
Up to 7.1.4
Version 7.0.0
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.3 beta
Version 7.0.4
Version 7.0.5
Version 7.0.6
Version 7.0.7
Version 7.0.8
Version 7.0.9
Version 7.1.0
Version 7.1.0 b1
Version 7.1.0 b2
Version 7.1.1
Version 7.1.2
Version 7.1.3

References (6)

Timeline

No history available yet.