View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 13562 | Bug reports | Security | public | 2018-04-02 16:58 | 2018-04-06 11:47 |
| Reporter | strukt93 | Assigned To | |||
| Priority | none | Severity | minor | ||
| Status | closed | Resolution | fixed | ||
| Fixed in Version | 3.6.x | ||||
| Summary | 13562: CSRF in box deletion | ||||
| Description | This issue allows an attacker to CSRF an administrator into deleting a box, the following is the vulnerable request: http://HOST/limesurvey/index.php/admin/homepagesettings/sa/delete/id/ID The last parameter in the path, ID, should be replaced with the appropriate box ID for successful exploitation. | ||||
| Tags | No tags attached. | ||||
| Bug heat | 252 | ||||
| Complete LimeSurvey version number (& build) | 3.0.0-beta.3+17110 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | MariaDB | ||||
| Server OS (if known) | Linux/Windows | ||||
| Webserver software & version (if known) | Apache2 | ||||
| PHP Version | 7.0 | ||||
|
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=26925 |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2018-04-02 16:58 | strukt93 | New Issue | |
| 2018-04-05 13:39 |
|
Assigned To | => markusfluer |
| 2018-04-05 13:39 |
|
Status | new => resolved |
| 2018-04-05 13:39 |
|
Resolution | open => fixed |
| 2018-04-05 13:39 |
|
Fixed in Version | => 3.6.x |
| 2018-04-05 14:29 |
|
Changeset attached | => LimeSurvey master d36a92d4 |
| 2018-04-05 14:29 |
|
Note Added: 47343 | |
| 2018-04-06 11:47 |
|
Status | resolved => closed |