Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/5250c4b1-132b-4da6-9bd6-db36cb56bea0 | exploit third party advisory patch |
https://github.com/froxlor/froxlor/commit/bbe82286aae21328668f24857995a67598fe978a | third party advisory patch |