An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/verbb/comments/blob/craft-3/CHANGELOG.md#155---2020-05-28-critical | third party advisory release notes |