Vulnerability Details CVE-2011-5074
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.4%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2011-5074
-
cpe:2.3:a:sitracker:support_incident_tracker:1.8.00
-
cpe:2.3:a:sitracker:support_incident_tracker:2.8.00
-
cpe:2.3:a:sitracker:support_incident_tracker:3.00
-
cpe:2.3:a:sitracker:support_incident_tracker:3.01
-
cpe:2.3:a:sitracker:support_incident_tracker:3.02
-
cpe:2.3:a:sitracker:support_incident_tracker:3.03
-
cpe:2.3:a:sitracker:support_incident_tracker:3.03a
-
cpe:2.3:a:sitracker:support_incident_tracker:3.04a
-
cpe:2.3:a:sitracker:support_incident_tracker:3.05
-
cpe:2.3:a:sitracker:support_incident_tracker:3.06
-
cpe:2.3:a:sitracker:support_incident_tracker:3.07
-
cpe:2.3:a:sitracker:support_incident_tracker:3.21
-
cpe:2.3:a:sitracker:support_incident_tracker:3.22
-
cpe:2.3:a:sitracker:support_incident_tracker:3.22pl1
-
cpe:2.3:a:sitracker:support_incident_tracker:3.23
-
cpe:2.3:a:sitracker:support_incident_tracker:3.24
-
cpe:2.3:a:sitracker:support_incident_tracker:3.30
-
cpe:2.3:a:sitracker:support_incident_tracker:3.31
-
cpe:2.3:a:sitracker:support_incident_tracker:3.32
-
cpe:2.3:a:sitracker:support_incident_tracker:3.33
-
cpe:2.3:a:sitracker:support_incident_tracker:3.35
-
cpe:2.3:a:sitracker:support_incident_tracker:3.36
-
cpe:2.3:a:sitracker:support_incident_tracker:3.40
-
cpe:2.3:a:sitracker:support_incident_tracker:3.41
-
cpe:2.3:a:sitracker:support_incident_tracker:3.45
-
cpe:2.3:a:sitracker:support_incident_tracker:3.50
-
cpe:2.3:a:sitracker:support_incident_tracker:3.51
-
cpe:2.3:a:sitracker:support_incident_tracker:3.6
-
cpe:2.3:a:sitracker:support_incident_tracker:3.60
-
cpe:2.3:a:sitracker:support_incident_tracker:3.61
-
cpe:2.3:a:sitracker:support_incident_tracker:3.62
-
cpe:2.3:a:sitracker:support_incident_tracker:3.63
-
cpe:2.3:a:sitracker:support_incident_tracker:3.64