Acc · Acc Statistics · CVE-2009-4905
**Name of the Vulnerable Software and Affected Versions**
Acc Statistics version 1.1
**Description**
The issue allows remote attackers to hijack the authentication of administrators for requests that change passwords, usernames, and e-mail addresses due to multiple cross-site request forgery (CSRF) vulnerabilities in index.php.
**Recommendations**
For Acc Statistics version 1.1, as a temporary workaround, consider restricting access to the index.php file until a patch is available. Avoid using the affected index.php file for administrative tasks that involve changing sensitive information, such as passwords, usernames, and e-mail addresses, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.