« Back to list

CVE-2009-4787

Status: ModifiedMedium (6.8)—

Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrators for requests that create user accounts or have unspecified other impact.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2009-4787",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-04-21T14:30:00.990",
  "references": [
    {
      "url": "http://holisticinfosec.org/content/view/130/45/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37349",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.pligg.com/blog/775/pligg-cms-1-0-3-release/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://holisticinfosec.org/content/view/130/45/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37349",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.pligg.com/blog/775/pligg-cms-1-0-3-release/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrators for requests that create user accounts or have unspecified other impact."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en Pligg anterior a v1.0.3, permite a atacantes remotos secuestrar la autenticación de administradores para peticiones que crean cuentas de usuario o puede tener otro tipo de impacto no especificado."
    }
  ],
  "lastModified": "2026-06-16T23:14:21.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53A36D0E-7A52-4BAF-9A66-F104891360C8",
              "versionEndIncluding": "1.0.2"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "887009EA-90B6-4324-A028-F4045AE959CC"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1ECEA2B-5C36-45A1-BBBB-431D289F90BB"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "690ACAF2-0786-4410-943D-A2188D0E376E"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A46AB541-94BC-484E-A0DF-C7AB0900AA74"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA67A543-4F90-490B-841A-8FC5E799585E"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.0:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1335A76B-76DF-4C93-B2FF-699A7FD4B48F"
            },
            {
              "criteria": "cpe:2.3:a:pligg:pligg_cms:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BC1036D-627B-42AC-8B2B-D44D72B3B5A1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}