PT-2009-3870 · Twiki · Twiki

Ashcrow

+2

·

Published

2009-04-30

·

Updated

2017-08-17

·

CVE-2009-1339

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TWiki versions prior to 4.3.1
Description A cross-site request forgery issue allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages. This can be achieved by using a URL for a save script in the SRC attribute of an IMG element.
Recommendations For versions prior to 4.3.1, update to version 4.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the save script to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1339

Affected Products

Twiki