CVE-2012-5992
published 2012-12-19CVE-2012-5992: Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
1.78%
75.7th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3p7v-42w7-qvff: Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2012-6007 [MEDIUM] CWE-79 GHSA-3p7v-42w7-qvff: Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
GHSA
GHSA-44pq-x8pr-ff7r: Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7
ghsa_unreviewed·2022-05-17
CVE-2012-5992 [MEDIUM] CWE-352 GHSA-44pq-x8pr-ff7r: Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.
Cisco
Cisco Wireless LAN Controller Cross-Site Request Forgery Vulnerability
vendor_cisco·2012-12-13·CVSS 6.8
CVE-2012-5992 [MEDIUM] CWE-352 Cisco Wireless LAN Controller Cross-Site Request Forgery Vulnerability
Cisco Wireless LAN Controller Cross-Site Request Forgery Vulnerability
Cisco Wireless LAN Controller (WLC) Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site request forgery attacks on a targeted system.
The vulnerability is due to insufficient sanitization of user-supplied input processed by the WLC management web interface of the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could allow the attacker to gain unauthorized access to the affected application, which could be used to conduct further attacks.
Cisco confirmed the vulnerability in a security bug report; however, software updates are not available.
No detection rules found.
No writeups or analysis indexed.
2012-12-19
Published