CVE-2013-2628 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed) possibly before 1.5 Stable allow remote attackers to hijack the authentication of administrators for unspecified requests related to the lack of an anti-CSRF token.

Reference

http://osvdb.org/101154 http://seclists.org/bugtraq/2013/Dec/107 http://www.csnc.ch/misc/files/advisories/CSNC-2013-005-006-007_Leed_Multiple_vulns.txt

Share on: