7.5
CVSSv3

CVE-2017-9415

Published: 21/07/2017 Updated: 25/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view.

Vulnerable Product Search on Vulmon Subscribe to Product

subsonic subsonic 6.1.1

Exploits

[+] Credits: John Page aka hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/SUBSONIC-PASSWORD-RESET-CSRFtxt [+] ISR: ApparitionSec Vendor: ================ wwwsubsonicorg Product: =============== subsonic v611 Subsonic is a media streaming server You install it on y ...
Subsonic media streaming server can allow a remote attacker to reset account passwords if usernames are known and victims click a malicious link ...