CVE-2016-4504: Meteocontrol Weblog

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.

Affected products

Published 2017-03-21. Last modified 2026-06-17.