CVE-2023-7038

MEDIUM4.3EPSS 0.14%

Cross-Site Request Forgery (CSRF) in automad/automad

Published: 12/21/2023Modified: 8/19/2024
Also known as:GHSA-4j8w-p6hv-3qxc

Description

automad up to 1.10.9 does not implement anti-CSRF tokens by default, making it vulnerable Cross-Site Request Forgery (CSRF). An attacker may exploit this vulnerability to force an admin into creating or deleting users. An exploit has been disclosed publicly.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References (5)