CVE-2012-5004: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the authentication of admins for requests that (1) add group plans via admin/groupplans.html or (2) add extra packages via admin/extrapacks/createextrapack.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5004?
CVE-2012-5004 is classified as a medium severity vulnerability due to its potential to allow unauthorized actions by remote attackers.
How can I fix CVE-2012-5004?
To fix CVE-2012-5004, update Parallels H-Sphere to the latest version provided by the vendor that addresses this CSRF vulnerability.
What types of attacks are possible with CVE-2012-5004?
CVE-2012-5004 allows attackers to perform actions like adding group plans and extra packages by hijacking admin session authentication.
Who is affected by CVE-2012-5004?
CVE-2012-5004 affects installations of Parallels H-Sphere version 3.3 Patch 1.
Is CVE-2012-5004 a widespread vulnerability?
CVE-2012-5004 may not be widespread but poses a significant risk for users of the affected Parallels H-Sphere version.