CVE-2018-11538
01.06.2018, 19:29
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
Vendor | Product | Version |
---|---|---|
searchblox | searchblox | 8.6.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References