CVE-2011-5074: Sitracker Support Incident Tracker
Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.
Affected products
- Sitracker Support Incident Tracker: up to and including 3.64; version 3.6 only; version 3.21 only; version 3.22 only; version 3.22pl1 only; version 3.23 only; …
Published 2012-01-29. Last modified 2026-06-16.