
                 Summary: XSRF
                 Project: Savannah Administration
            Submitted by: tajh
            Submitted on: Fr 09 Okt 2009 08:12:04 GMT
                Category: Trackers (bugs, support, tasks...)
                Priority: 5 - Normal
                Severity: 6 - Security
                  Status: None
             Assigned to: None
        Originator Email: 
        Operating System: None
             Open/Closed: Open
         Discussion Lock: Any



There seems to be a XSRF bug in the software, which allows attackers to
inject spam flaggings into savannah when savannah users visit the attackers
webpage, for example with the following code:

Could someone please verify this and place a token into the URL, like it's
done on Wikipedia?


Reply to this item at:


  Nachricht geschickt von/durch Savannah

Reply via email to