peter bassill · operator
$ cve CVE-2015-6493 JSON

CVE-2015-6493 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 70)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.32% — more likely to be exploited than 70% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2015-10-28
Last modified2026-06-17

Affected (1)

VendorProduct
infinite automation systemsmango automation

Public exploits

SourceTitleDate
exploit-dbMango Automation 2.6.0 - Multiple Vulnerabilities2015-09-28

References

→ the Explorer  ·  watch your stack  ·  NVD