PT-2006-5369 · Unknown · Address Book
Published
2006-12-31
·
Updated
2017-07-20
·
CVE-2006-4582
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
The Address Book version 1.04e
Description
A cross-site request forgery issue allows remote attackers to perform unauthorized actions as other users. This can be achieved by manipulating the
id parameter in a deleteuser action within the users.php file, potentially leading to the deletion of arbitrary users.Recommendations
For version 1.04e, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent unauthorized actions. As a temporary workaround, restrict access to the
users.php file and the deleteuser action to minimize the risk of exploitation. Avoid using the id parameter in the deleteuser action until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Address Book