Back to Database
Status published
Medium
CVE-2008-3716
Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows...
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unspecified component.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3716
Credits & Attribution
No credits recorded in the NVD database.
References
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6427
- http://sourceforge.net/project/shownotes.php?release_id=619864
- http://www.securityfocus.com/bid/30706
- http://sourceforge.net/tracker/index.php?func=detail&aid=2040513&group_id=82171&atid=1098812
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44483
- http://secunia.com/advisories/31503
Affected Vendor
harmoni
View all reports →Affected Software
harmoni
Vulnerable Versions:
0, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.1.0, 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.5.1, 0.6.0, 0.6.2, 0.7.0, 0.7.1, 0.7.2, 0.7.6, 0.7.7, 0.9.0, 0.10.1, 0.11.0, 0.12.0, 0.12.1, 0.12.3, 0.13.0, 0.13.1, 0.13.2, 0.13.3, 0.13.4, 0.13.5, 0.13.6, 0.13.7, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.5, 1.0.6, 1.1.0, 1.3.0, 1.3.2, 1.3.4, 1.3.5, 1.4.2, 1.4.6
Timeline
Official Publish:
August 19th, 2008
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.