CVE-2016-3653
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.
- Affected products
- Symantec Endpoint Protection Client, Symantec Endpoint Protection Manager, Symantec Endpoint Protection Server
- Symantec Endpoint Protection Manager
- ≤ 12.1.6
- Fix
- Available
- CVSS 3.0
- 8.0 HIGH
- EPSS
- 1.3% (69th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2016-06-30
CVE-2016-3653 at NVD
4 known exploits for CVE-2016-3653
Proof-of-concept code and exploit modules indexed by Sploitus