Back to search
CVE-2013-6173
Published: Nov 21, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions in (1) xAdmin or (2) xDashboard.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20131119 ESA-2013-078: EMC Document Sciences xPression Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
1029384
vdb-entry
x_refsource_SECTRACK
99985
vdb-entry
x_refsource_OSVDB
VU#346982
third-party-advisory
x_refsource_CERT-VN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now