CVE-2012-2380: Apache Roller
Medium severity, CVSS 6.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
Affected products
- Apache Roller: up to and including 5.0; version 0.9.5 only; version 0.9.6 only; version 0.9.6.3 only; version 0.9.6.4 only; version 0.9.7 only; …
Published 2012-06-26. Last modified 2026-06-16.