PT-2014-7012 · Torrentflux · Torrentflux
Nicolas Guigo
·
Published
2014-09-05
·
Updated
2020-01-30
·
CVE-2014-6029
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TorrentFlux version 2.4
Description
The issue allows remote authenticated users to delete or modify other users' cookies. This can be achieved by manipulating the
cid parameter in an editCookies action to the "profile.php" endpoint.Recommendations
For TorrentFlux version 2.4, consider restricting access to the
cid parameter in the editCookies action to prevent unauthorized modification or deletion of cookies. As a temporary workaround, restrict access to the "profile.php" endpoint until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Torrentflux