CVE-2018-7634: CSRF
An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the application, leading to account takeover.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7634?
CVE-2018-7634 is a vulnerability in Enalean Tuleap 9.17 that allows attackers to perform CSRF attacks to change a user's registered email address, potentially leading to account takeover.
What is the severity of CVE-2018-7634?
The severity of CVE-2018-7634 is rated as high, with a CVSS score of 8.8.
How does CVE-2018-7634 affect Enalean Tuleap 9.17?
CVE-2018-7634 affects Enalean Tuleap 9.17 by not mitigating CSRF attacks when changing an email address, which can be exploited by attackers to abuse the functionality.
How can the CVE-2018-7634 vulnerability be exploited?
The CVE-2018-7634 vulnerability can be exploited by performing a CSRF attack to make a victim change their registered email address on the Enalean Tuleap 9.17 application.
Is there a fix for CVE-2018-7634?
Yes, a fix for CVE-2018-7634 is available. It is recommended to update Enalean Tuleap to a version that includes the necessary mitigation measures.