Deluge CVE-2017-7178 Cross Site Request Forgery Vulnerability



Deluge is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.

Exploiting this issue allows a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.

Versions prior to Deluge 1.3.14 are vulnerable.

Information

Bugtraq ID: 97041
Class: Design Error
CVE: CVE-2017-7178

Remote: Yes
Local: No
Published: Mar 21 2017 12:00AM
Updated: May 19 2017 07:59PM
Credit: Kyle Neideck.
Vulnerable: Gentoo Linux
Deluge Deluge 1.3.13
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64


Not Vulnerable: Deluge Deluge 1.3.14


Exploit


An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.


Related Posts

Comments