First published: Thu Apr 30 2009(Updated: )
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foswiki Foswiki | =1.0.0 | |
Foswiki Foswiki | =1.0.2 | |
Foswiki Foswiki | =1.0.3 | |
Foswiki Foswiki | =1.0.1 | |
Foswiki Foswiki | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.