Description
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8629 | CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header. |
References
| Link | Providers |
|---|---|
| https://github.com/ysrc/xunfeng/issues/177 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:32:54.009Z
Reserved: 2018-09-11T00:00:00.000Z
Link: CVE-2018-16832
No data.
Status : Modified
Published: 2018-09-11T13:29:01.450
Modified: 2024-11-21T03:53:24.413
Link: CVE-2018-16832
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD