An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Piwik is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input by an unspecified script. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
Disclosure Timeline:
Published: Oct 21 2012 12:00AM
Updated: Oct 21 2012 12:00AM