vendor:
Latitude
by:
RedTeam Pentesting
3,3
CVSS
LOW
Cross-Site Request Forgery
352
CWE
Product Name: Latitude
Affected Version From: 2.2.2
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2014-2399
CPE: endeca:latitude
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Advisory: Endeca Latitude Cross-Site Request Forgery
Endeca Latitude offers administrators the ability to perform different administrative and configuration operations by accessing URLs. These URLs are not secured by a randomly generated token and therefore are prone to Cross-Site Request Forgery attacks. An attacker might prepare a website, which can trigger arbitrary functionality (see [1] and [2]) of an Endeca Latitude instance if someone opens the attacker's website in a browser that can reach Endeca Latitude.
Mitigation:
The vendor has decided not to fix this vulnerability.