cbcvebase.
CVE-2013-6443
published 2014-01-23

CVE-2013-6443: CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site…

PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.60%
44.8th percentile
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

Affected

3 ranges
VendorProductVersion rangeFixed in
redhatcloudforms
redhatcloudforms_3.0_management_engine<= 5.2.1
redhatcloudforms_3.0_management_engine

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.