CVE-2012-4051

JAMF Casper Suite < 8.61 - Cross-Site Request Forgery via Save Action

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4051. PoCs published by Jacob Holcomb.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in JAMF Casper Suite MDM, allowing an attacker to create a new admin user or modify an existing one via a crafted HTML form. The exploit submits a POST request to the target server with predefined user details, bypassing authentication.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.

Exploits (1)

exploitdb WORKING POC
by Jacob Holcomb · textwebappsjsp
https://www.exploit-db.com/exploits/21545

This exploit demonstrates a CSRF vulnerability in JAMF Casper Suite MDM, allowing an attacker to create a new admin user or modify an existing one via a crafted HTML form. The exploit submits a POST request to the target server with predefined user details, bypassing authentication.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: JAMF Casper Suite (version not specified)
No auth needed
Prerequisites: Victim must be authenticated in the Casper Suite web interface · Attacker must trick victim into visiting a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/555668

Scores

EPSS 0.0147
EPSS Percentile 70.3%

Details

CWE
CWE-352
Status published
Products (13)
jamf/casper_suite 7.0
jamf/casper_suite 7.1
jamf/casper_suite 7.2
jamf/casper_suite 7.3
jamf/casper_suite 8.0
jamf/casper_suite 8.1
jamf/casper_suite 8.2
jamf/casper_suite 8.3
jamf/casper_suite 8.4
jamf/casper_suite 8.5
... and 3 more
Published Sep 28, 2012
Tracked Since Feb 18, 2026