CVE-2015-4460

Boxautomation C2box < 4.0.0 - CSRF

Title source: rule
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors.

Exploits (1)

exploitdb WORKING POC
by Wissam Bashour · textwebappsasp
https://www.exploit-db.com/exploits/37447

References (5)

Core 5
Core References
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37447/
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535861/30/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75569

Scores

EPSS 0.0032
EPSS Percentile 54.9%

Details

CWE
CWE-352
Status published
Products (1)
boxautomation/c2box < 4.0.0
Published Jul 16, 2015
Tracked Since Feb 18, 2026