Skip to content


Subversion checkout URL

You can clone with
Download ZIP


User change language should check for token (reported by Merlin Mayr) #3733

mattab opened this Issue · 2 comments

3 participants


Reported by email

I recently discovered an Cross Site Request Forgery-Flaw in the source code of the Piwik Code (Version 1.10.1). The flaw is located in the LanguagesManager-Plugin, here is the vulnerable part of code (Controller.php): public function saveLanguage()
The function does not check if the logged in user really wanted to change the language, there is no CSRF-Protection. It is possible to change the actual language, without having access to the Dashboard of Piwik, this could result in confused users, some users may think they got hacked and somebody else changed the current language.

we should add token_auth check to avoid CSRF on this.


In c2f670c: Fixes possible minor CSRF that potentially allowed attackers to
change a users language.

fixes #3733


In c8f11dd: Refs #3733 Installer was broken because there is not yet a token_auth during installer, disabling csrf protectionif piwik is not installed

@mattab mattab added this to the 1.11 - Piwik 1.11 milestone
@halfdan halfdan was assigned by mattab
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Something went wrong with that request. Please try again.