CVE-2017-11567: Cesanta Mongoose Embedded Web Server Library

High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.

Affected products

  • Cesanta Mongoose Embedded Web Server Library: up to and including 6.8

Published 2017-09-07. Last modified 2026-06-17.