Description
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
CVSS vector
AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4 Affected Packages4 packages
🔴Vulnerability Details
3GHSAGHSA-h9pm-h729-wj6q: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3↗2022-05-05 ▶ OSVsamba vulnerabilities↗2016-03-08 ▶ OSVCVE-2013-0214: Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3↗2013-02-02 ▶ 📋Vendor Advisories
4CISA ICSOmron NS Series HMI Vulnerabilities↗2019-01-31 ▶ UbuntuSamba vulnerabilities↗2016-03-08 ▶ Red Hatsamba: cross-site request forgery vulnerability in SWAT↗2013-01-30 ▶ DebianCVE-2013-0214: samba - Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration ...↗2013 ▶ 💬Community
3BugzillaCVE-2013-0213 CVE-2013-0214 samba various flaws [fedora-all]↗2013-01-30 ▶ BugzillaCVE-2013-0213 CVE-2013-0214 samba4 various flaws [fedora-17]↗2013-01-30 ▶ BugzillaCVE-2013-0214 samba: cross-site request forgery vulnerability in SWAT↗2013-01-30 ▶