CVE-2015-2912 describes a vulnerability in the JSONP endpoint of the Studio component in OrientDB Server Community Edition versions prior to 2.0.15 and 2.1.1. This flaw allows remote attackers to conduct Cross-Site Request Forgery (CSRF) attacks and access sensitive information due to improper restriction of callback values. With a CVSS score of 8.8 (High), this vulnerability has a low attack complexity and can lead to high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, it has received some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.14CPE matchmatch criteria | cpe:2.3:a:orientdb:orientdb:*:*:*:*:community:*:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:a:orientdb:orientdb:2.1.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.