User Cake Cross Site Request Forgery Vulnerability
BID:67604
Info
User Cake Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 67604 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3866 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2014 12:00AM |
| Updated: | May 29 2014 01:29AM |
| Credit: | Dolev Farhi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
User Cake Cross Site Request Forgery Vulnerability
User Cake is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
User Cake 2.0.2 is vulnerable; prior versions may also be affected.
User Cake is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
User Cake 2.0.2 is vulnerable; prior versions may also be affected.
Exploit / POC
User Cake Cross Site Request Forgery Vulnerability
To exploit this issue the attacker needs to entice a user into following a malicious URI.
The following exploit is available:
To exploit this issue the attacker needs to entice a user into following a malicious URI.
The following exploit is available:
Solution / Fix
User Cake Cross Site Request Forgery Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
User Cake Cross Site Request Forgery Vulnerability
References:
References: