CVE-2016-4808: CSRF
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
Other sources
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged-in administrator into performing unwanted actions i.e An attacker can trick a victim into disable the installed application just by visiting a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4808?
CVE-2016-4808 is classified as a medium severity vulnerability due to its potential to allow CSRF attacks.
How do I fix CVE-2016-4808?
To fix CVE-2016-4808, upgrade your web2py installation to version 2.14.6 or later.
What versions of web2py are affected by CVE-2016-4808?
CVE-2016-4808 affects web2py versions 2.14.5 and below.
What kind of attacks can be executed due to CVE-2016-4808?
CVE-2016-4808 can enable attackers to execute Cross Site Request Forgery attacks, tricking users into performing unwanted actions.
Who is impacted by CVE-2016-4808?
Users of web2py versions 2.14.5 and below who are logged in can be impacted by CVE-2016-4808.