First published: Thu Aug 28 2014(Updated: )
TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TorrentFlux | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6028 is classified as a medium severity vulnerability due to its potential impact on user privacy.
To fix CVE-2014-6028, update to a newer version of TorrentFlux that addresses this vulnerability.
CVE-2014-6028 affects users of TorrentFlux version 2.4 who are remotely authenticated.
CVE-2014-6028 is a vulnerability that allows remote authenticated users to access other users' cookies.
A patch for CVE-2014-6028 can be obtained by upgrading to a version of TorrentFlux that fixes the issue.