Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.34%
Published
Jun 30, 2016
Modified
May 6, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.
Weaknesses (CWE)
Affected Products (1)
References (8)