CVE-2013-5748

Simplerisk < 20130915-001 - CSRF

Title source: rule
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action.

Exploits (1)

exploitdb WORKING POC
by Ryan Dewhurst · textwebappsphp
https://www.exploit-db.com/exploits/28656

Scores

EPSS 0.0025
EPSS Percentile 48.1%

Details

CWE
CWE-352
Status published
Products (1)
simplerisk/simplerisk < 20130915-001
Published May 12, 2014
Tracked Since Feb 18, 2026