6.8
CVSSv2

CVE-2017-7556

Published: 17/08/2017 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote malicious users to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hawt hawtio 1.5.3

Vendor Advisories

It was found that hawtio contains a CSRF flaw that allows unrelated websites to perform actions as the authenticated user Attackers could use this vulnerability to trick the user to visit his website that contains a malicious script which can be submitted to hawtio server on behalf of the user ...