Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.
References
Configurations
Information
Published : 2015-09-03 10:59
Updated : 2018-10-09 12:57
NVD link : CVE-2015-6545
Mitre link : CVE-2015-6545
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
webgroupmedia
- cerb