First published: Wed Apr 22 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts, aka Bug ID CSCus97494.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified MeetingPlace | =8.6\(1.9\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0705 is classified as a medium severity vulnerability.
To fix CVE-2015-0705, upgrade to the latest version of Cisco Unified MeetingPlace that addresses this vulnerability.
CVE-2015-0705 affects Cisco Unified MeetingPlace version 8.6(1.9).
CVE-2015-0705 allows remote attackers to perform cross-site request forgery (CSRF) attacks.
Attackers can hijack the authentication of administrators and create administrative accounts through CVE-2015-0705.