Required CVE Record Information
Description
The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified vectors related to the "URL of a RSS feed of the user."
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 54681 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: authenexternalauth-url-sec-bypass(77213) vdb-entryx_transferred
- secunia.com: 50060 third-party-advisoryx_transferred
- lists.bestpractical.com: [rt-announce] 20120725 Security vulnerabilities in three commonly deployed RT extensions mailing-listx_transferred