First published: Fri Nov 15 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/spip | 3.2.4-1+deb10u9 3.2.4-1+deb10u11 3.2.11-3+deb11u9 3.2.11-3+deb11u7 4.1.9+dfsg-1+deb12u2 4.1.12+dfsg-1 | |
Spip | <=2.1.23 | |
Spip | =2.0.0 | |
Spip | =2.0.1 | |
Spip | =2.0.2 | |
Spip | =2.0.3 | |
Spip | =2.0.4 | |
Spip | =2.0.5 | |
Spip | =2.0.6 | |
Spip | =2.0.7 | |
Spip | =2.0.8 | |
Spip | =2.0.9 | |
Spip | =2.0.10 | |
Spip | =2.0.11 | |
Spip | =2.0.12 | |
Spip | =2.0.13 | |
Spip | =2.0.14 | |
Spip | =2.0.15 | |
Spip | =2.0.16 | |
Spip | =2.0.17 | |
Spip | =2.0.18 | |
Spip | =2.0.19 | |
Spip | =2.0.20 | |
Spip | =2.0.21 | |
Spip | =2.0.22 | |
Spip | =2.1.1 | |
Spip | =2.1.2 | |
Spip | =2.1.3 | |
Spip | =2.1.4 | |
Spip | =2.1.5 | |
Spip | =2.1.6 | |
Spip | =2.1.7 | |
Spip | =2.1.8 | |
Spip | =2.1.9 | |
Spip | =2.1.10 | |
Spip | =2.1.11 | |
Spip | =2.1.12 | |
Spip | =2.1.13 | |
Spip | =2.1.14 | |
Spip | =2.1.15 | |
Spip | =2.1.16 | |
Spip | =2.1.17 | |
Spip | =2.1.18 | |
Spip | =2.1.19 | |
Spip | =2.1.20 | |
Spip | =2.1.21 | |
Spip | =2.1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4555 is classified as a moderate severity vulnerability due to its potential for cross-site request forgery attacks.
To fix CVE-2013-4555, update your SPIP installation to at least version 2.1.24 or any later versions provided.
CVE-2013-4555 affects versions of SPIP prior to 2.1.24, including all versions from 2.0.0 up to 2.1.23.
CVE-2013-4555 can allow an attacker to log out authenticated users without their consent, potentially disrupting user sessions.
While the best solution is to update, temporarily restricting access to the logout functionality can mitigate the risk of CVE-2013-4555.