CVE-2012-4051 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.47% — more likely to be exploited than 73% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-09-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jamf | casper suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JAMF Casper Suite MDM - Cross-Site Request Forgery | 2012-09-27 |
References
- http://infosec42.blogspot.com/2012/09/jamf-casper-suite-mdm-csrf-vulnerability.html
- http://jamfsoftware.com/libraries/pdf/products/documentation/Casper_Suite_8.61_Release_Notes.pdf
- http://www.kb.cert.org/vuls/id/555668
- http://infosec42.blogspot.com/2012/09/jamf-casper-suite-mdm-csrf-vulnerability.html
- http://jamfsoftware.com/libraries/pdf/products/documentation/Casper_Suite_8.61_Release_Notes.pdf
- http://www.kb.cert.org/vuls/id/555668
→ the Explorer · watch your stack · NVD