First published: Fri Oct 05 2018(Updated: )
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system via a web browser and with the privileges of the user.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Hosted Collaboration Mediation Fulfillment | =11.5\(2\) | |
Cisco Hosted Collaboration Mediation Fulfillment | =11.5\(3\) | |
Cisco Hosted Collaboration Mediation Fulfillment | =12.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15401 is a vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment that allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
CVE-2018-15401 has a severity rating of medium, with a severity value of 6.5.
An attacker can exploit CVE-2018-15401 by tricking a user into clicking on a specially crafted link or visiting a malicious website, which triggers a CSRF attack and allows the attacker to perform unauthorized actions on the system.
Versions 11.5(2), 11.5(3), and 12.5(1) of Cisco Hosted Collaboration Mediation Fulfillment are affected by CVE-2018-15401.
Yes, Cisco has released a security advisory with mitigation measures for CVE-2018-15401. It is recommended to apply the necessary patches or updates provided by Cisco to address this vulnerability.