CVE-2012-6047: x7 Group x7 Chat
Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page in an adminpanel action to index.php.
Affected products
- x7 Group x7 Chat: up to and including 2.0.5.1; version 1.0.0b only; version 1.1.1b only; version 1.1.2b only; version 1.2.0b only; version 1.3.0b only; …
Published 2012-11-27. Last modified 2026-06-16.