First published: Thu Jul 05 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Message Filter | <=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0303 is classified as a medium severity vulnerability due to its potential for CSRF attacks.
To fix CVE-2012-0303, users should upgrade to the latest version of Symantec Message Filter that addresses this vulnerability.
CVE-2012-0303 enables cross-site request forgery (CSRF) attacks, which can lead to unauthorized command execution and admin account creation.
CVE-2012-0303 affects users of Symantec Message Filter version 6.3 and prior.
Yes, CVE-2012-0303 can allow remote attackers to hijack the authentication of arbitrary authenticated users.