{"api_version":"1","generated_at":"2026-07-23T08:17:35+00:00","cve":"CVE-2009-3022","urls":{"html":"https://cve.report/CVE-2009-3022","api":"https://cve.report/api/cve/CVE-2009-3022.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3022","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3022"},"summary":{"title":"CVE-2009-3022","description":"Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-08-31 20:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-352","n/a","CWE-352 CWE-352 Cross-Site Request Forgery (CSRF)"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52838","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.bingo-cms.jp/security/jvn68640473.html","name":"http://www.bingo-cms.jp/security/jvn68640473.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"bingo!CMS 脆弱性情報-TOP | クロスサイトリクエストフォージェリの脆弱性(2009.08.27)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN68640473/index.html","name":"http://jvn.jp/en/jp/JVN68640473/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"JVN#68640473 bingo!CMS core and bingo!CMS vulnerable to cross-site request forgery","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html","name":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/57425","name":"http://osvdb.org/57425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/36458","name":"http://secunia.com/advisories/36458","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"bingo!CMS Cross-Site Request Forgery Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3022","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3022","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3022","vulnerable":"1","versionEndIncluding":"1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"itd-inc","cpe5":"bingo\\!cms","cpe6":"*","cpe7":"-","cpe8":"commercial","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3022","vulnerable":"1","versionEndIncluding":"1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"itd-inc","cpe5":"bingo\\!cms","cpe6":"*","cpe7":"-","cpe8":"core","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:14:55.370Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"bingocms-unspecified-csrf(52838)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52838"},{"name":"57425","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/57425"},{"name":"JVNDB-2009-000058","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.bingo-cms.jp/security/jvn68640473.html"},{"name":"JVN#68640473","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN68640473/index.html"},{"name":"36458","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36458"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2009-3022","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-01-21T16:08:52.291144Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-352","description":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-01-21T16:08:56.507Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"bingocms-unspecified-csrf(52838)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52838"},{"name":"57425","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/57425"},{"name":"JVNDB-2009-000058","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.bingo-cms.jp/security/jvn68640473.html"},{"name":"JVN#68640473","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN68640473/index.html"},{"name":"36458","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36458"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3022","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"bingocms-unspecified-csrf(52838)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/52838"},{"name":"57425","refsource":"OSVDB","url":"http://osvdb.org/57425"},{"name":"JVNDB-2009-000058","refsource":"JVNDB","url":"http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html"},{"name":"http://www.bingo-cms.jp/security/jvn68640473.html","refsource":"CONFIRM","url":"http://www.bingo-cms.jp/security/jvn68640473.html"},{"name":"JVN#68640473","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN68640473/index.html"},{"name":"36458","refsource":"SECUNIA","url":"http://secunia.com/advisories/36458"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3022","datePublished":"2009-08-31T20:00:00.000Z","dateReserved":"2009-08-31T00:00:00.000Z","dateUpdated":"2025-01-21T16:08:56.507Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-08-31 20:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-352","n/a","CWE-352 CWE-352 Cross-Site Request Forgery (CSRF)"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:itd-inc:bingo\\!cms:*:-:commercial:*:*:*:*:*","versionEndIncluding":"1.2","matchCriteriaId":"F782FA95-6C66-4A3E-AE0E-AD4419A89C80"},{"vulnerable":true,"criteria":"cpe:2.3:a:itd-inc:bingo\\!cms:*:-:core:*:*:*:*:*","versionEndIncluding":"1.2","matchCriteriaId":"C8D7A923-B0C6-4660-A204-7FB68CBE78A2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3022","Ordinal":"1","Title":"CVE-2009-3022","CVE":"CVE-2009-3022","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3022","Ordinal":"1","NoteData":"Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.","Type":"Description","Title":"CVE-2009-3022"},{"CveYear":"2009","CveId":"3022","Ordinal":"2","NoteData":"2009-08-31","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3022","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}