Symantec Gateway CSRF Admin Backdoor Flaw
ID: 91cb06ea-1c48-5bbe-85a5-45a88ca0e75b
STIX ID: report--91cb06ea-1c48-5bbe-85a5-45a88ca0e75b
Feed Name: NCC Research
Threat Score
Symantec Messaging Gateway 9.5.3-3 is affected by a CSRF vulnerability that allows an attacker to create a backdoor administrator account (via a crafted image tag) because GET/POST are interchangeable, sensitive functions lack password protection, and there is no CSRF protection; the report includes a proof-of-concept and notes that a fix was released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
