CVE Published: 20/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: icscert |
Vendor: n/a |
Product: Schneider Electric Wonderware InTouch Access Anywhere Status : PUBLISHED
CVE-2017-5156 Description
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.