First published: Sun Apr 20 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ikiwiki Hosting Project | <=2.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0165 is categorized as a medium severity vulnerability due to the potential for unauthorized preference modifications.
To fix CVE-2008-0165, upgrade Ikiwiki to version 2.42 or later.
CVE-2008-0165 is associated with cross-site request forgery (CSRF) attacks that allow modification of user preferences.
CVE-2008-0165 affects all versions of Ikiwiki prior to 2.42.
Attackers exploiting CVE-2008-0165 can modify user preferences, including sensitive information like passwords.