CVE-2013-5748: Simplerisk
Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action.
Affected products
- Simplerisk Simplerisk: up to and including 20130915-001
Published 2014-05-12. Last modified 2026-06-16.