Description
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Progress Software / LoadMaster7.2.55.0 – 7.2.59.3 ( LoadMaster GA)
- Progress Software / LoadMaster7.2.49.0 – 7.2.54.9 ( LoadMaster LTSF)
- Progress Software / LoadMaster7.2.48.10 – 7.2.48.11 (LoadMaster LTS)
- Progress Software / LoadMaster7.1.35.10 – 7.1.35.11 (LoadMaster MT)
Updated 28m ago · 8 sources