vendor:
SnapGear Management Console SG560
by:
LiquidWorm
N/A
CVSS
N/A
Cross-Site Request Forgery
Unknown
CWE
Product Name: SnapGear Management Console SG560
Affected Version From: 3.1.5u1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: fnord/1.9, Apache 1.3.27 (Unix), Linux 2.4.31
2020
SnapGear Management Console SG560 3.1.5 – Cross-Site Request Forgery (Add Super User)
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Unknown