peter bassill · operator
$ cve CVE-2010-3024 JSON

CVE-2010-3024 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.44% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2010-08-16
Last modified2026-06-16

Affected (1)

VendorProduct
hulihanapplicationsdiamondlist

Public exploits

SourceTitleDate
exploit-dbDiamondList 0.1.6 - Cross-Site Request Forgery2010-08-05

References

→ the Explorer  ·  watch your stack  ·  NVD