Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
BID:37066
Info
Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
| Bugtraq ID: | 37066 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2009 12:00AM |
| Updated: | Nov 19 2009 03:45PM |
| Credit: | JVN credits Yoshinari Fukumoto of Rakuten, Inc. |
| Vulnerable: |
Redmine Redmine 0.8.6 Redmine Redmine 0.8.5 |
| Not Vulnerable: |
Redmine Redmine 0.8.7 |
Discussion
Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
Redmine is prone to multiple remote issues, including a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker could exploit these issues to steal cookie-based authentication credentials or perform unauthorized actions masquerading as the victim. Other attacks are also possible.
These issues affect versions prior to Redmine 0.8.7.
Redmine is prone to multiple remote issues, including a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker could exploit these issues to steal cookie-based authentication credentials or perform unauthorized actions masquerading as the victim. Other attacks are also possible.
These issues affect versions prior to Redmine 0.8.7.
Exploit / POC
Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
An attacker can use a browser to exploit these issues. The attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can use a browser to exploit these issues. The attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Redmine Cross Site Scripting And Request Forgery Remote Vulnerabilities
References:
References:
- Redmine Changelog (Redmine)
- Redmine Homepage (Redmine)
- Redmine vulnerable to cross-site request forgery (JVN)
- Redmine vulnerable to cross-site scripting (JVN)