CVE-2009-3520

8.8
HIGHCVSS v3.1 Base Score
0.65%
LOW RiskEPSS (49th percentile)

Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.

Published: 10/1/2009
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

0.65%LOW Exploitation Risk
49th percentile

This vulnerability has a 0.65% probability of being exploited in the next 30 days, ranking higher than 49% of all scored CVEs.

CWE Classification

Advertisement