First published: Fri Sep 05 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenDb OpenDb | =1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3938 is classified as a medium severity vulnerability due to its potential for unauthorized password changes.
To fix CVE-2008-3938, upgrade Open Media Collectors Database to a version that has addressed this CSRF vulnerability.
CVE-2008-3938 can be exploited through cross-site request forgery attacks allowing attackers to change user passwords.
Users of Open Media Collectors Database version 1.0.6 are affected by CVE-2008-3938.
You can detect CVE-2008-3938 by reviewing the logs for unusual password change requests or by checking the version of Open Media Collectors Database installed.