Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120626_00
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/54133
Scores
EPSS
0.0028
EPSS Percentile
51.8%
Details
CWE
CWE-352
Status
published
Products (1)
symantec/message_filter
< 6.3
Published
Jul 05, 2012
Tracked Since
Feb 18, 2026