CVE-2010-4729
N/A
N/A
Summary
Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-site request forgery (CSRF) attacks via multiple form submissions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://code.zikula.org/core/ticket/1979
- http://code.zikula.org/core12/browser/tags/Zikula-1.2.5/src/docs/CHANGELOG
References
- http://code.zikula.org/core/ticket/1979
- http://code.zikula.org/core12/browser/tags/Zikula-1.2.5/src/docs/CHANGELOG
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.