peter bassill · operator
$ cve CVE-2011-0535 JSON

CVE-2011-0535 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.43% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2011-02-08
Last modified2026-06-16

Affected (1)

VendorProduct
zikulazikula application framework

Public exploits

SourceTitleDate
exploit-dbZikula CMS 1.2.4 - Cross-Site Request Forgery2011-02-02

References

→ the Explorer  ·  watch your stack  ·  NVD