Cross-site request forgery (CSRF) vulnerability in Foswiki prior to 1.0.5 allows remote malicious users to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
foswiki foswiki 1.0.1 |
||
foswiki foswiki 1.0.2 |
||
foswiki foswiki 1.0.3 |
||
foswiki foswiki |
||
foswiki foswiki 1.0.0 |