Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/d01f0726-1a0f-4575-ae17-4b5319b11c29 | issue tracking patch exploit third party advisory |
https://github.com/yourls/yourls/commit/1de256d8694b0ec7d4df2ac1d5976d4055e09d59 | third party advisory patch |