{"api_version":"1","generated_at":"2026-07-24T19:35:00+00:00","cve":"CVE-2010-2345","urls":{"html":"https://cve.report/CVE-2010-2345","api":"https://cve.report/api/cve/CVE-2010-2345.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2345","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2345"},"summary":{"title":"CVE-2010-2345","description":"Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-06-21 15:30:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://holisticinfosec.org/content/view/146/45/","name":"http://holisticinfosec.org/content/view/146/45/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"holisticinfosec.org - HIO-2010-0523 odCMS Multiple Vulnerabilities","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59248","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59248","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/39942","name":"http://secunia.com/advisories/39942","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"odCMS Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/65263","name":"http://www.osvdb.org/65263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2345","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2345","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2345","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"odcms","cpe5":"odcms","cpe6":"1.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:32:16.423Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"39942","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39942"},{"name":"65263","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/65263"},{"name":"odcms-password-csrf(59248)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59248"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://holisticinfosec.org/content/view/146/45/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-06-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"39942","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39942"},{"name":"65263","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/65263"},{"name":"odcms-password-csrf(59248)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59248"},{"tags":["x_refsource_MISC"],"url":"http://holisticinfosec.org/content/view/146/45/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2345","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"39942","refsource":"SECUNIA","url":"http://secunia.com/advisories/39942"},{"name":"65263","refsource":"OSVDB","url":"http://www.osvdb.org/65263"},{"name":"odcms-password-csrf(59248)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59248"},{"name":"http://holisticinfosec.org/content/view/146/45/","refsource":"MISC","url":"http://holisticinfosec.org/content/view/146/45/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2345","datePublished":"2010-06-21T15:00:00.000Z","dateReserved":"2010-06-21T00:00:00.000Z","dateUpdated":"2024-08-07T02:32:16.423Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-21 15:30:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:odcms:odcms:1.06:*:*:*:*:*:*:*","matchCriteriaId":"C836620E-1E96-4E01-B419-516172369FFE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2345","Ordinal":"1","Title":"CVE-2010-2345","CVE":"CVE-2010-2345","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2345","Ordinal":"1","NoteData":"Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests.","Type":"Description","Title":"CVE-2010-2345"},{"CveYear":"2010","CveId":"2345","Ordinal":"2","NoteData":"2010-06-21","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2345","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}