CVE-2016-4504 Vulnerability Details
/
/
/
CVE-2016-4504 Metadata Quick Info
CVE Published: 21/03/2017 |
CVE Updated: 06/08/2024 |
CVE Year: 2016
Source: icscert |
Vendor: n/a |
Product: Meteocontrol WEB\'log
Status : PUBLISHED
CVE-2016-4504 Description
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB\'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CSRF
Source: n/a
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).