First published: Tue Feb 21 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0235.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | <=6.0 | |
Advantech WebAccess | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1235 has been classified as a medium severity vulnerability due to its potential for remote exploitation by authenticated users.
To mitigate CVE-2012-1235, users should upgrade to the latest version of Advantech WebAccess provided by the vendor.
CVE-2012-1235 affects users of Advantech WebAccess versions 6.0 and below, as well as version 5.0.
CVE-2012-1235 is a cross-site request forgery (CSRF) vulnerability that allows authenticated users to hijack other users' sessions.
Yes, CVE-2012-1235 is related to CVE-2012-0235, as it results from an incomplete fix for that prior vulnerability.