Interface is not protected by a CSRF token, making it vulnerable for malicious actions such as rebooting the
appliances via this interface. this attack could be setup up by a concealed iframe pointing to code loaded from a remote hostile server.
Below an illustration:
<< picture available >>
Internal reference : M11
↧
the WCG 7.7.3. mgmt interface is not protected by a CSRF token
↧