Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Internet Radio Settings via the urlRedirectCustomUrl parameter to networkSettings.view. NOTE: These vulnerabilities can be exploited to conduct server-side request forgery (SSRF) attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Subsonic | Subsonic | 6.1.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/142794/Subsonic-6.1.1-Server-Side-Request-FExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42118/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/142794/Subsonic-6.1.1-Server-Side-Request-FExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42118/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-9413?
CVE-2017-9413 is a vulnerability with a CVSS score of 8.8 (HIGH). Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a po...
How severe is CVE-2017-9413?
CVE-2017-9413 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9413?
Check the references section above for vendor advisories and patch information. Affected products include: Subsonic Subsonic.