CVE-2012-4051

Jamf Casper Suite < 8.6 - CSRF

Title source: rule
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.

Exploits (1)

exploitdb WORKING POC
by Jacob Holcomb · textwebappsjsp
https://www.exploit-db.com/exploits/21545

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/555668

Scores

EPSS 0.0165
EPSS Percentile 82.1%

Details

CWE
CWE-352
Status published
Products (13)
jamf/casper_suite 7.0
jamf/casper_suite 7.1
jamf/casper_suite 7.2
jamf/casper_suite 7.3
jamf/casper_suite 8.0
jamf/casper_suite 8.1
jamf/casper_suite 8.2
jamf/casper_suite 8.3
jamf/casper_suite 8.4
jamf/casper_suite 8.5
... and 3 more
Published Sep 28, 2012
Tracked Since Feb 18, 2026