First published: Fri Mar 14 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP System Management Homepage | =7.1 | |
HP System Management Homepage | =7.2 | |
HP System Management Homepage | =7.2.1 | |
HP System Management Homepage | =7.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6188 is considered a medium severity vulnerability due to its potential to allow remote attackers to hijack authentication.
To fix CVE-2013-6188, it is recommended to upgrade to a later version of HP System Management Homepage that addresses this CSRF vulnerability.
CVE-2013-6188 can enable attackers to perform unauthorized actions on behalf of victims through cross-site request forgery.
CVE-2013-6188 affects HP System Management Homepage versions 7.1 through 7.2.2.
Exploitation of CVE-2013-6188 may be relatively straightforward given that it relies on CSRF techniques, which can be common in web applications.