« Volver al listado

CVE-2009-1802

Estado: ModificadaMedia (6.8)—

Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1802",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-05-28T14:30:00.377",
  "references": [
    {
      "url": "http://freepbx.org/trac/ticket/3660",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/54262",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34857",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://freepbx.org/trac/ticket/3660",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/54262",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34857",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en FreePBX 2.5.1, y otros 2.4.x, 2.5.x, y versiones pre-lanzamiento 2.6.x, permiten a atacantes remotos secuestrar la autenticación de administradores en peticiones que crean una nueva cuenta de administrador o tener otros impactos no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:08:05.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "455E97D6-B069-49D6-B510-3D4112A9E1B3"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.0_beta1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF1E1278-3114-4BD1-B589-30B5313C9502"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.0_beta2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32D216B0-31D6-4288-8773-FB2438944492"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A09E3F0-E1A6-4CC4-8134-89DF5DB6EA3B"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B2C1156-93B6-4D71-8D9C-ED6FC6C0AE74"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0_beta1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11ACC1C9-A2C3-41CA-B608-C474B642A380"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8A021AB-A142-4DAD-9EB0-2352C625D8CC"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C0B173F-2161-4E40-A712-90DA6B997820"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "613A39A4-976E-4535-9408-533F957F7F87"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5B657C6-A2DF-432A-9F46-1157C630CB20"
            },
            {
              "criteria": "cpe:2.3:a:sangoma:freepbx:2.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9734B50E-BEA8-41DF-835F-7B15A9BB31E8"
            },
            {
              "criteria": "cpe:2.3:a:sangoma:freepbx:2.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9645D4F-BB03-49AD-AE79-6FE990BF18FE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}