Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-02-08 14:00
Updated : 2011-09-21 20:28
NVD link : CVE-2011-0535
Mitre link : CVE-2011-0535
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
zikula
- zikula_application_framework