CVE-2011-5074 - CVE House
Back to Database
Status published Medium CVE-2011-5074

Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker...

Vulnerability Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-5074

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

support incident tracker
Vulnerable Versions:
0, 3.6, 3.21, 3.22, 3.22pl1, 3.23, 3.24, 3.30, 3.31, 3.32, 3.33, 3.35, 3.36, 3.40, 3.41, 3.45, 3.50, 3.51, 3.60, 3.61, 3.62, 3.63

Timeline

Official Publish: January 29th, 2012
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.