Flyspray · Flyspray · CVE-2012-1058
**Name of the Vulnerable Software and Affected Versions**
Flyspray version 0.9.9.6
**Description**
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an "admin.newuser" action to "index.php".
**Recommendations**
For Flyspray version 0.9.9.6, consider implementing CSRF protection mechanisms, such as tokens, to prevent unauthorized requests. As a temporary workaround, restrict access to the "admin.newuser" action in "index.php" to minimize the risk of exploitation.