Skip to content

CVE-2013-7352

Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0028 (0.3%)
Percentil: 51.4%
EPSS: 2026-05-06

Afecta

b2evolution:b2evolution

Descripción técnica

Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.

Publicada: 2/4/2014, 18:55:21
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo