Unrated severityNVD Advisory· Published Dec 10, 2008· Updated Apr 23, 2026
CVE-2008-5400
CVE-2008-5400
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers.
Affected products
20cpe:2.3:a:mvnforum:mvnforum:*:ga:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:mvnforum:mvnforum:*:ga:*:*:*:*:*:*range: <=1.2
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:rc3_01:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_beta2:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_beta3:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_rc1:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_rc2:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_rc3_01:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_rc4:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.0_rc4_04:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0.2.:ga:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0_ga:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.0_rc4:*:*:*:*:*:*:*
- cpe:2.3:a:mvnforum:mvnforum:1.1:ga:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/32931nvdVendor Advisory
- www.mvnforum.com/mvnforum/viewthread_thread%2C4361nvdURL Repurposed
- archives.neohapsis.com/archives/fulldisclosure/2008-12/0061.htmlnvd
- osvdb.org/50404nvd
- security.bkis.vnnvd
- securityreason.com/securityalert/4699nvd
- www.securityfocus.com/archive/1/498872/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/47027nvd
News mentions
0No linked articles in our index yet.