CVE-2012-0990

low
Published 2012-02-07 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://sourceforge.net/projects/dclassifieds/files/csrf_fix_120105.rar/download

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/47691

Application impact

VendorProductVersionsFixed
dclassifiedsdclassifieds0.1

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.