CVE-2015-6493 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 70)
Patch early
A public exploit exists.
Description
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 1.32% — more likely to be exploited than 70% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-10-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| infinite automation systems | mango automation |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mango Automation 2.6.0 - Multiple Vulnerabilities | 2015-09-28 |
References
→ the Explorer · watch your stack · NVD