CVE-2013-2713

medium
Published 2014-05-23 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.krisonav.com/index.php?module=articles_show&articles_id=release-notes

Application impact

VendorProductVersionsFixed
krisonavkrisonav{"endIncluding":"3.0.1"}
krisonavkrisonav0.9.3
krisonavkrisonav0.9.4
krisonavkrisonav0.9.5
krisonavkrisonav0.9.6
krisonavkrisonav0.9.7
krisonavkrisonav1.0.0
krisonavkrisonav1.0.1
krisonavkrisonav1.0.2
krisonavkrisonav1.1.35
krisonavkrisonav2.0.1
krisonavkrisonav2.1.3
krisonavkrisonav2.1.5
krisonavkrisonav2.1.6
krisonavkrisonav3.0.0

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.