peter bassill · operator
$ cve CVE-2012-0699 JSON

CVE-2012-0699 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 3.6% (pctl 89)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.57% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2018-01-11
Last modified2026-06-16

Affected (1)

VendorProduct
haudenschiltfamily connections cms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD