Cross-Site Request Forgery Vulnerability in Google App Engine Python SDK
CVE-2011-1364

Currently unrated

Key Information:

Vendor
Google
Vendor
CVE Published:
30 October 2011

Summary

A CSRF vulnerability exists in the Interactive Console of the Google App Engine Python SDK prior to version 1.5.4. This flaw allows remote attackers to hijack an administrator's authentication and execute arbitrary Python code by manipulating requests through the code parameter. Attackers can exploit this vulnerability to gain unauthorized access and execute malicious commands within the SDK's environment, potentially compromising the integrity of applications utilizing the affected SDK.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.