CVE-2009-3759
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- citrix/xencenterweb
- Source
- cve@mitre.org
References
- http://securenetwork.it/ricerca/advisory/download/SN-2009-01.txtBroken Link
- http://securitytracker.com/id?1022520Broken Link, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9106Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/504764Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35592Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1814Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51576Third Party Advisory, VDB Entry
- http://securenetwork.it/ricerca/advisory/download/SN-2009-01.txtBroken Link
- http://securitytracker.com/id?1022520Broken Link, Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9106Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/504764Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35592Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1814Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51576Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.