Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/65b5a243-3f0c-4df3-9bab-898332180968 | exploit third party advisory patch |
https://github.com/microweber/microweber/commit/63447b369973724f0d352a006f25af6ff71ae292 | third party advisory patch |