Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
BID:61601
Info
Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 61601 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3450 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2013 12:00AM |
| Updated: | Aug 02 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified Communications Manager 9.1 Cisco Unified Communications Manager 9.0 Cisco Unified Communications Manager 8.6 Cisco Unified Communications Manager 8.5 |
| Not Vulnerable: | |
Discussion
Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
Cisco Unified Communications Manager is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and to gain unauthorized access to the affected application.
This issue is being tracked by Cisco bug ID CSCui13028.
Cisco Unified Communications Manager versions 8.5, 8.6, 9.0, and 9.1 are vulnerable.
Cisco Unified Communications Manager is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and to gain unauthorized access to the affected application.
This issue is being tracked by Cisco bug ID CSCui13028.
Cisco Unified Communications Manager versions 8.5, 8.6, 9.0, and 9.1 are vulnerable.
Exploit / POC
Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
To exploit the issue an attacker must entice a user into visiting a malicious site.
To exploit the issue an attacker must entice a user into visiting a malicious site.
Solution / Fix
Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified Communications Manager CVE-2013-3450 Cross Site Request Forgery Vulnerability
References:
References: