Cross-Site Request Forgery Vulnerability in Cisco Hosted Collaboration Mediation Fulfillment
CVE-2016-6454

6.5MEDIUM

Key Information:

Summary

A cross-site request forgery (CSRF) vulnerability exists in the web interface of Cisco's Hosted Collaboration Mediation Fulfillment application. This flaw permits an unauthenticated remote attacker to execute unauthorized actions without user consent, potentially compromising the integrity of the application. It is essential for users and administrators of affected systems to implement security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Cisco Hosted Collaboration Mediation Fulfillment before 11.5(0.98000.216) Cisco Hosted Collaboration Mediation Fulfillment before 11.5(0.98000.216)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.