CVE-2012-4051
JAMF Casper Suite < 8.61 - Cross-Site Request Forgery via Save Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4051. PoCs published by Jacob Holcomb.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in JAMF Casper Suite MDM, allowing an attacker to create a new admin user or modify an existing one via a crafted HTML form. The exploit submits a POST request to the target server with predefined user details, bypassing authentication.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in JAMF Casper Suite MDM, allowing an attacker to create a new admin user or modify an existing one via a crafted HTML form. The exploit submits a POST request to the target server with predefined user details, bypassing authentication.