CVE-2013-7251: Projectforge
Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/.
Affected products
- Projectforge Projectforge: up to and including 5.2; version 5.0 only; version 5.1 only
Published 2014-01-02. Last modified 2026-06-17.