CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable.
CVE
CVE-2011-1911
Severity
MEDIUM
CVSS
6.8
EPSS
1.49%
Original NVD Description
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.