CVE-2006-5878

HIGH7.5EPSS 1.8%

Edgewall Trac Cross-site request forgery (CSRF) vulnerability

Published: 5/1/2022Modified: 11/18/2024
Also known as:GHSA-2q26-r8c4-jfx5DEBIAN-CVE-2006-5878PYSEC-2006-3

Description

Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (15)