CVE-2012-3343: CSRF
Cross-site request forgery (CSRF) vulnerability in Microdasys before 3.5.1-B708, as used in Bloxx Web Filtering before 5.0.14 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that trigger error pages containing XSS sequences, a different vulnerability than CVE-2012-2564.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3343?
CVE-2012-3343 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site request forgery (CSRF).
How do I fix CVE-2012-3343?
To fix CVE-2012-3343, upgrade Microdasys to version 3.5.1-B708 or later and ensure Bloxx Web Filtering is updated to version 5.0.14 or above.
What types of attacks can exploit CVE-2012-3343?
CVE-2012-3343 can be exploited through CSRF attacks that allow attackers to hijack user sessions and execute unauthorized actions.
Which software is affected by CVE-2012-3343?
CVE-2012-3343 affects Microdasys versions before 3.5.1-B708 and Bloxx Web Filtering versions up to and including 5.0.13.
What are the consequences of not patching CVE-2012-3343?
Failing to patch CVE-2012-3343 can result in unauthorized access to user accounts, leading to potential data breaches and other security incidents.