Sploitus

CVE-2017-14956

5 known exploits for CVE-2017-14956

AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or XLS format). Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.

Affected products
Alienvault Usm
Alienvault Unified Security Management
≤ 5.4.2
CVSS 3.0
5.7 MEDIUM
EPSS
1.9% (77th percentile)
Weakness
CWE-352
NVD status
Modified
Published
2017-10-18
CVE-2017-14956 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2017-14956

Proof-of-concept code and exploit modules indexed by Sploitus