GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
BID:59781
Info
GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 59781 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3513 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2013 12:00AM |
| Updated: | Mar 08 2013 12:00AM |
| Credit: | Johannes Greil of SEC Consult Unternehmensberatung GmbH |
| Vulnerable: |
GroundWork GroundWork Monitor Enterprise 6.7 |
| Not Vulnerable: | |
Discussion
GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
GroundWork Monitor Enterprise is prone to multiple cross-site request-forgery vulnerabilities because the application fails to properly validate HTTP requests.
Exploiting these issues may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Note: These issues were previously discussed in BID 58403 (GroundWork Monitor Enterprise 'Noma' Component Multiple Input Validation Vulnerabilities), but have been moved to their own record to better document them.
GroundWork Monitor Enterprise is prone to multiple cross-site request-forgery vulnerabilities because the application fails to properly validate HTTP requests.
Exploiting these issues may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Note: These issues were previously discussed in BID 58403 (GroundWork Monitor Enterprise 'Noma' Component Multiple Input Validation Vulnerabilities), but have been moved to their own record to better document them.
Exploit / POC
GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
GroundWork Monitor Enterprise CVE-2013-3513 Multiple Cross Site Request Forgery Vulnerabilities
References:
References:
- GroundWork Homepage (GroundWork)
- GroundWork Monitor 6.7.0 Enterprise Release Notes (GroundWork)
- Multiple critical vulnerabilities (part 1) (SEC Consult Vulnerability Lab)
- Multiple high risk vulnerabilities (part 2) (SEC Consult Vulnerability Lab)