AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-6801

HIGH · CVSS 8.8 EPSS 2.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-09-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-6801
Severity
HIGH
CVSS
8.8
EPSS
2.29%
Apache

Original NVD Description

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.