First published: Thu Apr 30 2009(Updated: )
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foswiki | <=1.0.4 | |
Foswiki | =1.0.0 | |
Foswiki | =1.0.1 | |
Foswiki | =1.0.2 | |
Foswiki | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1434 is considered a high severity vulnerability due to its ability to allow attackers to hijack user authentication.
To fix CVE-2009-1434, upgrade Foswiki to version 1.0.5 or later.
CVE-2009-1434 is classified as a cross-site request forgery (CSRF) vulnerability.
CVE-2009-1434 affects Foswiki versions up to and including 1.0.4.
Yes, CVE-2009-1434 can allow unauthorized users to change permissions and group memberships.