vendor:
Xerox Printer
by:
Ismail Tasdelen
N/A
CVSS
N/A
Cross-Site Request Forgery (Add Admin)
CSRF
CWE
Product Name: Xerox Printer
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
XEROX WorkCentre 6655 Printer – Cross-Site Request Forgery (Add Admin)
The CSRF vulnerability was discovered in the WorkCentre® 6655 printer model of Xerox printer hardware. A request to add users is made in the Device User Database form field. This request is captured by the proxy. And a CSRF PoC HTML file is prepared. Xerox WorkCentre® 6655 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)