Vulnerability Details CVE-2014-9502
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related to menu callbacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2014-9502
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.01
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.04
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.09
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.12
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.13
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.15
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.16
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.17
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.18
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.19
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.21
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.22
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.23
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.24
-
cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.25