CVE-2012-5891

medium
Published 2012-11-17 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user passwords via a change action, or (3) delete a user via a delete action.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
dalbumdalbum{"endIncluding":"1.44"}
dalbumdalbum1.03
dalbumdalbum1.3
dalbumdalbum1.04
dalbumdalbum1.05
dalbumdalbum1.06
dalbumdalbum1.07
dalbumdalbum1.08
dalbumdalbum1.09
dalbumdalbum1.10
dalbumdalbum1.20
dalbumdalbum1.21
dalbumdalbum1.22
dalbumdalbum1.31
dalbumdalbum1.32
dalbumdalbum1.33
dalbumdalbum1.34
dalbumdalbum1.35

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.