CVE-2013-3499: Gwos Groundwork Monitor
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access files via a crafted header.
Affected products
- Gwos Groundwork Monitor: version 6.7.0 only
Published 2013-05-08. Last modified 2026-06-16.