CVE-2015-4630
8.0
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.
Affected (4)
References (18)
Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory
Source: cve@mitre.org
ProductRelease NotesVendor Advisory
Source: cve@mitre.org
ProductRelease NotesVendor Advisory
Source: cve@mitre.org
ProductRelease NotesVendor Advisory
Source: cve@mitre.org
ProductRelease NotesVendor Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.