vendor:
FTGate v7
by:
hyp3rlinx
N/A
CVSS
N/A
Cross site request forgery (CSRF)
Unknown
CWE
Product Name: FTGate v7
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
FTGate v7 Cross Site Request Forgery (CSRF) Vulnerability
Multiple CSRF vectors exist within FTGate v7 allowing various attacks like adding arbitrary domains, enabling arbitrary remote archiving of logs, whitelisting arbitrary email addresses, adding arbitrary mailbox & disabling antivirus, and removing email attachment blocking for files.
Mitigation:
No information provided