Cross-Site Request Forgery Vulnerability in Google App Engine Python SDK
CVE-2011-1364
Currently unrated
Summary
A CSRF vulnerability exists in the Interactive Console of the Google App Engine Python SDK prior to version 1.5.4. This flaw allows remote attackers to hijack an administrator's authentication and execute arbitrary Python code by manipulating requests through the code parameter. Attackers can exploit this vulnerability to gain unauthorized access and execute malicious commands within the SDK's environment, potentially compromising the integrity of applications utilizing the affected SDK.
References
Timeline
Vulnerability published
Vulnerability Reserved