VYPR
Medium severity5.9NVD Advisory· Published Apr 10, 2020· Updated Jun 17, 2026

CVE-2019-18376

CVE-2019-18376

Description

A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.

Affected products

5
  • cpe:2.3:a:symantec:management_center:2.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:symantec:management_center:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:symantec:management_center:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:symantec:management_center:2.4:*:*:*:*:*:*:*
  • Symantec/MCdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.