CVE-2018-15569 describes a Cross-Site Request Forgery (CSRF) vulnerability in mylittleforum version 2.4.12, allowing for the unauthorized deletion of users. This medium-severity vulnerability, rated 6.5 on CVSSv3, requires user interaction (UI:R) and a network-based attack (AV:N) to achieve high integrity impact (I:H), meaning an attacker could delete users without their explicit consent. While the vulnerability has a low EPSS score and FAUCET Risk Score, indicating a low likelihood of exploitation in the wild, there is no known exploit code available in public databases like Metasploit or ExploitDB, and it has garnered no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.12CPE matchmatch criteria | cpe:2.3:a:mylittleforum:my_little_forum:2.4.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.