CVE-2017-6081: CSRF
Published Mar 13, 2017
·Updated
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.
Affected Software
5 affected components
Zammad Zammad<=1.0.3
Zammad Zammad=1.1.0
Zammad Zammad=1.1.1
Zammad Zammad=1.1.2
Zammad Zammad=1.2.0
Event History
Mar 13, 2017
CVE Published
via MITRE·06:14 AM
Data Sourced
via MITRE·06:14 AM
Description
Data Sourced
via NVD·06:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6081?
CVE-2017-6081 is classified as a medium severity vulnerability due to its ability to exploit cross-site request forgery.
2
How do I fix CVE-2017-6081?
To fix CVE-2017-6081, upgrade Zammad to version 1.0.4, 1.1.3, or 1.2.1 or later.
3
What software versions are vulnerable to CVE-2017-6081?
Versions of Zammad prior to 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1 are vulnerable to CVE-2017-6081.
4
What type of attack can leverage CVE-2017-6081?
CVE-2017-6081 allows an attacker to launch cross-domain requests to the REST API using a valid session cookie.
5
Is there a specific configuration required to exploit CVE-2017-6081?
An attacker needs a valid session cookie to successfully exploit CVE-2017-6081.