Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator, or insert arbitrary script via (1) user_profile_edit.php or (2) user_add.php.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Support_incident_tracker | Sitracker | * | 3.64 (including) |
Support_incident_tracker | Sitracker | 3.6 (including) | 3.6 (including) |
Support_incident_tracker | Sitracker | 3.21 (including) | 3.21 (including) |
Support_incident_tracker | Sitracker | 3.22 (including) | 3.22 (including) |
Support_incident_tracker | Sitracker | 3.22pl1 (including) | 3.22pl1 (including) |
Support_incident_tracker | Sitracker | 3.23 (including) | 3.23 (including) |
Support_incident_tracker | Sitracker | 3.24 (including) | 3.24 (including) |
Support_incident_tracker | Sitracker | 3.24-beta-2 (including) | 3.24-beta-2 (including) |
Support_incident_tracker | Sitracker | 3.30 (including) | 3.30 (including) |
Support_incident_tracker | Sitracker | 3.30-beta2 (including) | 3.30-beta2 (including) |
Support_incident_tracker | Sitracker | 3.31 (including) | 3.31 (including) |
Support_incident_tracker | Sitracker | 3.32 (including) | 3.32 (including) |
Support_incident_tracker | Sitracker | 3.33 (including) | 3.33 (including) |
Support_incident_tracker | Sitracker | 3.35 (including) | 3.35 (including) |
Support_incident_tracker | Sitracker | 3.35-beta1 (including) | 3.35-beta1 (including) |
Support_incident_tracker | Sitracker | 3.36 (including) | 3.36 (including) |
Support_incident_tracker | Sitracker | 3.40 (including) | 3.40 (including) |
Support_incident_tracker | Sitracker | 3.40-beta1 (including) | 3.40-beta1 (including) |
Support_incident_tracker | Sitracker | 3.41 (including) | 3.41 (including) |
Support_incident_tracker | Sitracker | 3.45 (including) | 3.45 (including) |
Support_incident_tracker | Sitracker | 3.45-beta1 (including) | 3.45-beta1 (including) |
Support_incident_tracker | Sitracker | 3.50 (including) | 3.50 (including) |
Support_incident_tracker | Sitracker | 3.50-beta1 (including) | 3.50-beta1 (including) |
Support_incident_tracker | Sitracker | 3.51 (including) | 3.51 (including) |
Support_incident_tracker | Sitracker | 3.60 (including) | 3.60 (including) |
Support_incident_tracker | Sitracker | 3.61 (including) | 3.61 (including) |
Support_incident_tracker | Sitracker | 3.62 (including) | 3.62 (including) |
Support_incident_tracker | Sitracker | 3.63 (including) | 3.63 (including) |
Support_incident_tracker | Sitracker | 3.63-beta1 (including) | 3.63-beta1 (including) |