CVE-2023-5444: CSRF in ePO leading to privilege escalation
A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the user interface. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this CSRF vulnerability?
The vulnerability ID for this CSRF vulnerability is CVE-2023-5444.
What is the severity of CVE-2023-5444?
The severity of CVE-2023-5444 is high (8 out of 10).
Which software version is affected by CVE-2023-5444?
The ePolicy Orchestrator version prior to 5.10.0 CP1 Update 2 is affected by CVE-2023-5444.
How can an attacker exploit this vulnerability?
To exploit this vulnerability, the attacker must perform a Cross Site Request Forgery attack.
Is there a fix available for CVE-2023-5444?
Yes, the fix for CVE-2023-5444 is to update ePolicy Orchestrator to version 5.10.0 CP1 Update 2 or later.