logo

Symantec Gateway CSRF Admin Backdoor Flaw

ID: 91cb06ea-1c48-5bbe-85a5-45a88ca0e75b

STIX ID: report--91cb06ea-1c48-5bbe-85a5-45a88ca0e75b

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-08-01

...
...

Symantec Messaging Gateway 9.5.3-3 is affected by a CSRF vulnerability that allows an attacker to create a backdoor administrator account (via a crafted image tag) because GET/POST are interchangeable, sensitive functions lack password protection, and there is no CSRF protection; the report includes a proof-of-concept and notes that a fix was released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.