Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2009-04-20T14:06:00
Updated: 2024-08-07T11:41:59.593Z
Reserved: 2009-04-20T00:00:00
Link: CVE-2008-6729

No data.

Status : Modified
Published: 2009-04-20T14:30:00.390
Modified: 2024-11-21T00:57:19.157
Link: CVE-2008-6729

No data.