User change language should check for token (reported by Merlin Mayr)
|Reported by:||matt||Owned by:||halfdan|
|Priority:||normal||Milestone:||1.11 - Piwik 1.11|
Description (last modified by halfdan)
Reported by email
I recently discovered an Cross Site Request Forgery-Flaw in the source code of the Piwik Code (Version 1.10.1). The flaw is located in the LanguagesManager-Plugin, here is the vulnerable part of code (Controller.php): public function saveLanguage()
The function does not check if the logged in user really wanted to change the language, there is no CSRF-Protection. It is possible to change the actual language, without having access to the Dashboard of Piwik, this could result in confused users, some users may think they got hacked and somebody else changed the current language.
we should add token_auth check to avoid CSRF on this.
Change History (5)
comment:3 Changed 15 months ago by Fabian Becker
- Resolution set to fixed
- Status changed from assigned to closed
comment:4 Changed 15 months ago by matt (mattab)
- Summary changed from User change language should check for token to User change language should check for token (reported by Merlin Mayr)