<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ticket search results</title><link>https://forge-allura.apache.org/p/allura/tickets/</link><description>You searched for labels:"CSRF"</description><language>en</language><lastBuildDate>Thu, 30 Jul 2015 22:41:21 -0000</lastBuildDate><item><title>Apache Allura Security Vulnerability</title><link>https://forge-allura.apache.org/p/allura/tickets/7944/</link><description>Hi,

My name is Mohamed Abdelbaset Elnoby a Senior Information Security Analyst and Web Application Penetration Tester at Seekurity Inc.

I would like to report a Security Vulnerability in the Apache Allura Wiki Script fetailed as follow:

Vulnerability:
Cross Site Request Forgery - (CSRF)

Info:
http://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)

Affected URL(s)/Forms Code:
/wiki/subscribe?subscribe=True
/wiki/subscribe?unsubscribe=True

More Details/Impact:
Force users to subscribe/unsubscribe to any other user's wiki, the vulnerable links shows a PoC links to do so to my wiki account.

Waiting for your reply

Best Regards,
Mohamed Abdelbaset Elnoby
Guru Programmer, Senior Information Security Consultant &amp; Web Application Penetration Tester at Seekurity Inc.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mohamed A. Baset</dc:creator><pubDate>Thu, 30 Jul 2015 22:41:21 -0000</pubDate><guid>https://forge-allura.apache.org/p/allura/tickets/7944/</guid></item></channel></rss>