vendor:
Microsoft Outlook Web Access
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Microsoft Outlook Web Access
Affected Version From: Microsoft Outlook Web Access for Exchange Server 2003
Affected Version To: Microsoft Outlook Web Access for Exchange Server 2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
Cross-Site Request Forgery in Microsoft Outlook Web Access for Exchange Server 2003
The vulnerability allows a remote attacker to perform actions in the context of an authorized user's session and gain unauthorized access to the affected application. The exploit involves submitting a form with hidden fields that perform certain actions.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches and updates provided by Microsoft.