Forum OpenACS Development: Re: Security Issue? Session Identifier Not Updated
Thanks a lot for the reply.
I was neither aware of the refreshing_p issue nor of the fix. I did read about the signature for session_id, but didn't understand the relevance to this issue.
I'll cross-link this answer from our forums. I'll also post an advisory for ]po[ V4.0 now.
OpenACS 5.9.0 fixes many more other attack vectors related with cross site scripting. The forthcoming OpenACS 5.9.1 addresses more injection attacks (both cross site scripting and SQL injection) identified with newer scanning and provides as well framework support for CSRF attacks (cross site request forgery)