CVE-2012-0699 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 3.6% (pctl 89)
Patch early
A public exploit exists.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.57% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| haudenschilt | family connections cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Family CMS 2.9 - Multiple Vulnerabilities | 2012-03-26 |
| exploit-db | Family CMS 2.7.2 - Multiple Persistent Cross-Site Scripting Vulnerabilities | 2011-12-10 |
→ the Explorer · watch your stack · NVD