Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the authentication of admins for requests that (1) add group plans via admin/group_plans.html or (2) add extra packages via admin/extra_packs/create_extra_pack.html.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://osvdb.org/78505 | vdb entry |
http://packetstormsecurity.org/files/view/108972/VL-392.txt | exploit |
http://secunia.com/advisories/47556 | third party advisory vendor advisory |
http://www.vulnerability-lab.com/get_content.php?id=392 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/72628 | vdb entry |