PT-2013-3859 · Light Feed · Leed

Alexandre Herzog

·

Publicado

2013-12-21

·

Atualizado

2013-12-23

·

CVE-2013-2628

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Leed (Light Feed) versions prior to 1.5 Stable
Description The issue is related to multiple cross-site request forgery (CSRF) vulnerabilities in the action.php file. These vulnerabilities could allow remote attackers to hijack the authentication of administrators for unspecified requests due to the lack of an anti-CSRF token.
Recommendations For versions prior to 1.5 Stable, update to version 1.5 Stable or later to resolve the issue. As a temporary workaround, consider implementing additional security measures to prevent CSRF attacks, such as validating request origins and verifying user intentions.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2628

Produtos afetados

Leed