ZeroHour

CVE-2016-3653

CVSS 3.0
8.0 high
EPSS
1%p70
Published
()
Modified
Description

Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.

Vendors
symantec
Products
endpoint protection manager
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.