The console in Togglz before 2.9.4 allows CSRF.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/advisories/GHSA-697v-pxg3-j262 | third party advisory |
https://github.com/togglz/togglz/pull/495 | third party advisory patch |
https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707 | third party advisory patch |