peter bassill · operator
$ cve CVE-2010-0713 JSON

CVE-2010-0713 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator for (1) requests that reset user passwords via zport/dmd/ZenUsers/admin, and (2) requests that change user commands, which allows for remote execution of system commands via zport/dmd/userCommands/.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.95% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2010-02-26
Last modified2026-06-16

Affected (1)

VendorProduct
zenosszenoss

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD