CVE Database · CVE-2009-4907
CVSS v3.1
N/A
EPSS
0.97%
Published
Jun 25, 2010
Modified
Apr 28, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.
Weaknesses (CWE)
Affected Products (1)
References (8)