CVE-2017-11567: Cesanta Mongoose Embedded Web Server Library
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.
Affected products
- Cesanta Mongoose Embedded Web Server Library: up to and including 6.8
Published 2017-09-07. Last modified 2026-06-17.