CVE-2009-1434: CSRF
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1434?
CVE-2009-1434 is considered a high severity vulnerability due to its ability to allow attackers to hijack user authentication.
How do I fix CVE-2009-1434?
To fix CVE-2009-1434, upgrade Foswiki to version 1.0.5 or later.
What type of vulnerability is CVE-2009-1434?
CVE-2009-1434 is classified as a cross-site request forgery (CSRF) vulnerability.
What versions of Foswiki are affected by CVE-2009-1434?
CVE-2009-1434 affects Foswiki versions up to and including 1.0.4.
Can CVE-2009-1434 affect user permissions?
Yes, CVE-2009-1434 can allow unauthorized users to change permissions and group memberships.