The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified vectors related to the "URL of a RSS feed of the user."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/54681 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77213 | vdb entry |
http://secunia.com/advisories/50060 | third party advisory vendor advisory |
http://lists.bestpractical.com/pipermail/rt-announce/2012-July/000208.html | mailing list patch vendor advisory |