CVE-2007-2338: CSRF
Published Apr 27, 2007
·Updated
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.
Affected Software
1 affected component
Phorum Phorum<=5.1.20
Remediation
Patch Available
Patch Available
Event History
Apr 27, 2007
CVE Published
04:19 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2338?
CVE-2007-2338 has a medium severity level due to its potential for unauthorized actions against the banlist.
2
How do I fix CVE-2007-2338?
To fix CVE-2007-2338, upgrade to Phorum version 5.1.22 or later which contains the necessary security patches.
3
What type of vulnerability is CVE-2007-2338?
CVE-2007-2338 is classified as a Cross-site Request Forgery (CSRF) vulnerability.
4
Who is affected by CVE-2007-2338?
Administrators using Phorum versions prior to 5.1.22 may be affected by CVE-2007-2338.
5
What can an attacker do with CVE-2007-2338?
An attacker can exploit CVE-2007-2338 to delete entries from the banlist without authorization.