mtons mblog
cpe:2.3:a:mblog_project:mblog:*:*:*:*:*:*:*
- 3.0
- 3.1
- 3.2
- 3.3
- 3.4
- 3.5.0
A cross-site request forgery (CSRF) vulnerability has been identified in Mtons Mblog versions through 3.5.0. This issue arises from a lack of CSRF protection, allowing attackers to exploit this weakness and potentially launch various attacks against admin users. The vulnerability can be exploited remotely and requires user interaction from the victim.
Exploitation of this vulnerability allows for cross-site request forgery, where an attacker can trick an admin user into performing actions without their consent. This could lead to unauthorized changes, such as altering user passwords or other sensitive information.
To reproduce this vulnerability, an attacker can create a form that submits a password change request to the admin user. This form can be automatically submitted using a script, effectively performing the action without the user's knowledge.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.