← back
CVE-2014-10014

CVE-2014-10014

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.0%
from disclosure to weapon0 days
Published on NVDJan 13
1st PoCJan 14
exploitation probability
2.0%top 22% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site scripting (XSS) attacks via the (2) event_title parameter in a create action to the AdminEvents controller or (3) category_title parameter in a create action to the AdminCategories controller.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.