CVE-2012-3343
Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error…
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error pages containing XSS sequences, a different vulnerability than CVE-2012-2564.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- bloxx/web filtering
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/722963US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBY
- http://www.kb.cert.org/vuls/id/722963US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8R9LBY
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.