CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-03-18T20:10:00

Updated: 2024-08-05T15:56:36.023Z

Reserved: 2017-03-18T00:00:00

Link: CVE-2017-7178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-03-18T20:59:00.203

Modified: 2020-07-08T17:40:08.337

Link: CVE-2017-7178

cve-icon Redhat

No data.