CVE-2017-6086 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities in ViMbAdmin 3.0.15, specifically within the addAction and purgeAction functions. These flaws allow remote attackers to hijack authenticated administrator sessions to perform various actions, including adding/removing administrators, changing passwords, and managing mailboxes or aliases. The vulnerability has a CVSSv3 score of 8.8 (HIGH), indicating a critical impact with high confidentiality, integrity, and availability compromise, requiring user interaction but with low attack complexity. While not listed on the KEV catalog and lacking active exploitation or significant community discussion, exploit code is publicly available via ExploitDB, suggesting a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.15CPE matchmatch criteria | cpe:2.3:a:vimbadmin:vimbadmin:3.0.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.