Impact
A cross‑site request forgery (CSRF) flaw in the Administrative User Interface of Progress MarkLogic Server allows an attacker to coerce an authenticated administrator into executing privileged actions without the administrator's knowledge. By tricking the administrator into visiting a malicious web page, the attacker can cause the browser to send administrative requests that the server accepts, leading to unauthorized changes to security settings such as authentication policies, access controls, and configuration parameters. The flaw is identified as CWE‑352 and represents a high‑severity vulnerability because it enables configuration tampering that can compromise the integrity of the server.
Affected Systems
Vulnerabilities affect Progress MarkLogic Server versions prior to 11.3.6 in the 11.x release line and prior to 12.0.3 in the 12.x line. Any deployment that has not upgraded to at least these patched releases and exposes the Admin UI externally is subject to risk. The flaw exists in the admin portal delivered by the product and does not require additional components beyond the standard installation.
Risk and Exploitability
The CVSS score of 7.5 marks this flaw as high severity. Because the EPSS score is not available, the exact probability of exploitation remains unclear, but the lack of a KEV listing suggests no publicly known exploit code has been observed yet. However, the remote attack requires only an authenticated administrator to be lured to a malicious page, a scenario that is common in phishing campaigns. Consequently, organizations running unpatched MarkLogic Server instances should consider the risk high until a fix is applied.
OpenCVE Enrichment