Unrated severityNVD Advisory· Published Sep 28, 2012· Updated Apr 29, 2026
CVE-2012-4051
CVE-2012-4051
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in editAccount.html in the JAMF Software Server (JSS) interface in JAMF Casper Suite before 8.61 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts or (2) change passwords via a Save action.
Affected products
13cpe:2.3:a:jamf:casper_suite:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:jamf:casper_suite:*:*:*:*:*:*:*:*range: <=8.6
- cpe:2.3:a:jamf:casper_suite:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:7.3:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.1:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.2:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.3:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.4:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.5:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.43:*:*:*:*:*:*:*
- cpe:2.3:a:jamf:casper_suite:8.51:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- infosec42.blogspot.com/2012/09/jamf-casper-suite-mdm-csrf-vulnerability.htmlnvdExploit
- jamfsoftware.com/libraries/pdf/products/documentation/Casper_Suite_8.61_Release_Notes.pdfnvdVendor Advisory
- www.kb.cert.org/vuls/id/555668nvdUS Government Resource
News mentions
0No linked articles in our index yet.