CVE-2011-2191Cross-Site Request Forgery in Cherokee

Severity
6.8MEDIUMNVD
EPSS
0.6%
top 30.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 7
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrated by a crafted nickname field to vserver/apply.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mfhm-xfg5-jwjm: Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 12022-05-17
CVEList
CVE-2011-2191: Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 12011-10-07

💬Community

3
Bugzilla
CVE-2011-2190 CVE-2011-2191 cherokee: multiple vulnerabilities [epel-all]2011-06-14
Bugzilla
CVE-2011-2190 CVE-2011-2191 cherokee: multiple vulnerabilities [fedora-all]2011-06-14
Bugzilla
CVE-2011-2191 cherokee: CSRF and XSS vulnerabilities2011-06-14
CVE-2011-2191 — Cross-Site Request Forgery in Cherokee | cvebase