vendor:
Secure Transport
by:
Emmanuel Law
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: Secure Transport
Affected Version From: Axway Secure Transport 5.2.1 SP2
Affected Version To: Axway Secure Transport 5.2.1 SP2
Patch Exists: YES
Related CWE: CVE-2013-7057
CPE: a:axway:secure_transport
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Axway Secure Transport 5.1 SP2 Arbitary File Upload via CSRF
It is possible to conduct CSRF on a user to upload arbitary files on the Axway Secure Transport server. This is due to the lack of anti-CSRF tokens in the web API. An adversary may exploit this to upload webshells for further attacks.
Mitigation:
Organizations should ensure that anti-CSRF tokens are implemented in the web API.