VYPR
Unrated severityNVD Advisory· Published May 21, 2015· Updated Jun 16, 2026

CVE-2012-1978

CVE-2012-1978

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delete an administrator via a request to auth/admin/adminprocess.php, (3) add an event via a request to engine/new_event.php, or (4) delete an event via a request to phpagenda/.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:simple_php_agenda_project:simple_php_agenda:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:simple_php_agenda_project:simple_php_agenda:*:*:*:*:*:*:*:*range: <=2.2.8
    • (no CPE)range: <=2.2.8

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.