CVE-2013-2778: Chatelao PHP Address Book

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests that delete accounts, a different vulnerability than CVE-2013-0135.1.

Affected products

  • Chatelao PHP Address Book: version 8.2.5 only

Published 2013-04-09. Last modified 2026-06-16.