Description: Some vulnerabilities have been reported in Zope, which can be exploited by malicious people to conduct cross-site request forgery attacks
The vulnerabilities are caused due to Zope allowing administrators to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. to add users or change user privileges by enticing a logged-in administrator to visit a malicious site.
The vulnerability is reported in all Zope versions up to and including 2.10.2.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.