ZeroHour

CVE-2016-4315

PoC ×3
CVSS 3.0
5.7 medium
EPSS
3%p86
Published
()
Modified
Description

Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

Vendors
wso2
Products
carbon
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.