Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Pacific Timesheet Cross-Site Request Forgery Vulnerability

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

4.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

4 years ago

Summary

This host is running Pacific Timesheet and is prone to cross-site request forgery vulnerability.

Insight

Insight

The flaw is due to improper validation of user-supplied input. A remote attacker could exploit this vulnerability to perform cross-site request forgery by tricking a logged in administrator into visiting a malicious web site or link to perform unauthorized actions.

Affected Software

Affected Software

Pacific Timesheet version 6.74 build 363.

Solution

Solution

Update to version 6.75 or later.

Common Vulnerabilities and Exposures (CVE)