Unrated severityNVD Advisory· Published Apr 30, 2009· Updated Apr 23, 2026
CVE-2009-1434
CVE-2009-1434
Description
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.
Affected products
5cpe:2.3:a:foswiki:foswiki:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:foswiki:foswiki:*:*:*:*:*:*:*:*range: <=1.0.4
- cpe:2.3:a:foswiki:foswiki:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:foswiki:foswiki:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:foswiki:foswiki:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:foswiki:foswiki:1.0.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- foswiki.org/Support/SecurityAlert-CVE-2009-1434nvdPatchVendor Advisory
- sourceforge.net/mailarchive/forum.phpnvdPatch
- secunia.com/advisories/34863nvdVendor Advisory
- osvdb.org/54148nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50256nvd
- launchpad.net/bugs/cve/2009-1434nvd
News mentions
0No linked articles in our index yet.