VYPR
Unrated severityNVD Advisory· Published Apr 30, 2009· Updated Apr 23, 2026

CVE-2009-1434

CVE-2009-1434

Description

Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.

Affected products

5
  • Foswiki/Foswiki5 versions
    cpe:2.3:a:foswiki:foswiki:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:foswiki:foswiki:*:*:*:*:*:*:*:*range: <=1.0.4
    • cpe:2.3:a:foswiki:foswiki:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:foswiki:foswiki:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:foswiki:foswiki:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:foswiki:foswiki:1.0.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.