CVE-2014-3896
Last modified
CVE-2014-3896 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Seeds | Acmailer | >= 3.8.0, < 3.8.17 |
| Seeds | Acmailer | >= 3.9.0, < 3.9.10 |
References
- http://jvn.jp/en/jp/JVN42511610/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000089Third Party Advisory, VDB Entry
- http://www.acmailer.jp/info/de.cgi?id=52Exploit, Vendor Advisory
- http://jvn.jp/en/jp/JVN42511610/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000089Third Party Advisory, VDB Entry
- http://www.acmailer.jp/info/de.cgi?id=52Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3896?
How severe is CVE-2014-3896?
How do I fix CVE-2014-3896?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3890silex SX-2000WG devices with firmware before 1.5.4 allow rem…
- CVE-2014-3891Buffer overflow in RimArts Becky! Internet Mail before 2.68 …
- CVE-2014-3892Cross-site scripting (XSS) vulnerability in Nexa Meridian be…
- CVE-2014-3893Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-3894Cross-site scripting (XSS) vulnerability in PHP Kobo Multifu…
- CVE-2014-3895The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier,…
- CVE-2014-3897Cross-site scripting (XSS) vulnerability in Homepage Decorat…
- CVE-2014-3898Cross-site scripting (XSS) vulnerability in Fujitsu ServerVi…
- CVE-2014-3899Gretech GOM Player 2.2.51.5149 and earlier allows remote att…
- CVE-2014-3900Cross-site scripting (XSS) vulnerability in admin/picture_mo…
- CVE-2014-3901Raritan Japan Dominion KX2-101 switches before 2 allow remot…
- CVE-2014-3902The CyberAgent Ameba application 3.x and 4.x before 4.5.0 fo…
Are you affected by CVE-2014-3896?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
