Cross-Site Request Forgery Vulnerability in Spring Batch Admin by Spring
CVE-2017-12881
8.8HIGH
What is CVE-2017-12881?
A cross-site request forgery (CSRF) vulnerability exists in Spring Batch Admin prior to version 1.3.0. This vulnerability enables remote attackers to potentially hijack user authentication and issue unauthorized requests. By exploiting this flaw, attackers could manipulate the application's functionalities, including the capability to upload files, leading to unauthorized access and control over the system.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved