Unrated severityNVD Advisory· Published Apr 2, 2014· Updated May 6, 2026
CVE-2013-7352
CVE-2013-7352
Description
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- b2evolution.net/news/2013/04/29/b2evolution-4-1-7-and-5-0-3nvdPatchVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2013-05/0004.htmlnvdExploit
- packetstormsecurity.com/files/121481/b2evolution-4.1.6-SQL-Injection.htmlnvdExploit
- www.htbridge.com/advisory/HTB23152nvdExploit
- osvdb.org/show/osvdb/92906nvd
News mentions
0No linked articles in our index yet.