CVE-2012-1235: CSRF
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1235?
CVE-2012-1235 has been classified as a medium severity vulnerability due to its potential for remote exploitation by authenticated users.
How do I fix CVE-2012-1235?
To mitigate CVE-2012-1235, users should upgrade to the latest version of Advantech WebAccess provided by the vendor.
Who is affected by CVE-2012-1235?
CVE-2012-1235 affects users of Advantech WebAccess versions 6.0 and below, as well as version 5.0.
What type of vulnerability is CVE-2012-1235?
CVE-2012-1235 is a cross-site request forgery (CSRF) vulnerability that allows authenticated users to hijack other users' sessions.
Is CVE-2012-1235 connected to any other vulnerabilities?
Yes, CVE-2012-1235 is related to CVE-2012-0235, as it results from an incomplete fix for that prior vulnerability.