A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the user interface. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: trellix

Published: 2023-11-17T09:47:20.014Z

Updated: 2023-11-17T09:59:39.706Z

Reserved: 2023-10-06T07:58:13.097Z


Link: CVE-2023-5444

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-17T10:15:07.723

Modified: 2023-11-29T19:31:17.210


Link: CVE-2023-5444

JSON object: View

cve-icon Redhat Information

No data.

CWE