VulnerabilityModified
CVE-2012-2564
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bloxx Web Filtering before 5.0.14 allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions.
MEDIUM 6.8EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bloxx Web Filtering before 5.0.14 allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- bloxx/web filtering
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/722963US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBYUS Government Resource
- http://www.securityfocus.com/bid/53715
- http://www.kb.cert.org/vuls/id/722963US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBYUS Government Resource
- http://www.securityfocus.com/bid/53715
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.