CVE-2009-1280: CSRF
Published Apr 9, 2009
·Updated
Multiple cross-site request forgery (CSRF) vulnerabilities in the commedia component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
14 affected components
Joomla joomla=1.5.5
Joomla joomla=1.5
Joomla joomla=1.5.7
Joomla joomla=1.5.0-beta2
Joomla joomla=1.5.9
Joomla joomla=1.5.3
Joomla joomla=1.5.2
Joomla joomla=1.5.0-beta1
Joomla joomla=1.5.8
Joomla joomla=1.5.1
Joomla joomla=1.5.4
Joomla joomla=1.5.0-rc1
Joomla joomla=1.5.6
Joomla joomla=1.5.0-beta
Event History
Apr 9, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1280?
CVE-2009-1280 is considered a high-severity vulnerability due to its potential for authentication hijacking.
2
How do I fix CVE-2009-1280?
To fix CVE-2009-1280, upgrade your Joomla installation to version 1.5.10 or later.
3
Who is affected by CVE-2009-1280?
CVE-2009-1280 affects Joomla versions 1.5.x through 1.5.9.
4
What types of attacks can exploit CVE-2009-1280?
CVE-2009-1280 can be exploited through cross-site request forgery (CSRF) attacks.
5
What components are involved in CVE-2009-1280?
The com_media component of Joomla is primarily associated with CVE-2009-1280.