CVE-2009-4898

Publication date 7 September 2010

Last updated 24 July 2024


Ubuntu priority

Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the ACTION attribute of a FORM element, in conjunction with a call to the submit method in the onload attribute of a BODY element. NOTE: this issue exists because of an insufficient fix for CVE-2009-1339.

Status

Package Ubuntu Release Status
twiki 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Ignored end of life