CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
References
Configurations
History
No history.
Information
Published : 2017-03-18 20:59
Updated : 2025-04-20 01:37
NVD link : CVE-2017-7178
Mitre link : CVE-2017-7178
CVE.ORG link : CVE-2017-7178
JSON object : View
Products Affected
debian
- debian_linux
deluge-torrent
- deluge
CWE
CWE-352
Cross-Site Request Forgery (CSRF)