Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentication of user for requests that delete a user via user_delete.php and other unspecified programs.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/576355 | third party advisory us government resource |
http://secunia.com/advisories/45437 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/50896 | vdb entry |
http://osvdb.org/show/osvdb/77657 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/71653 | vdb entry |