CVE-2012-5326

Loading...

General

Score:6.8/10.0
Severity:Medium
Category:Bounce Attack
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Medium
Authentication:None

Published on 08/10/12 - Updated on 29/08/17

Description

Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via an administrators action.

Category: Bounce Attack

CWE-352 (Cross-Site Request Forgery (CSRF))
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Security Notices

US National Vulnerability DatabaseCVE-2012-5326

Exploits

Exploit-DBEDB-18404

Relative technologies

VendorProduct
idevspotisupport

Share this vulnerability with:

Twitter Facebook LinkedIn Mail