A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://getferdi.com/ | product |
https://github.com/getferdi/ferdi | third party advisory |
https://gist.github.com/omriinbar-cyesec/c1179fe99725d2b828b6573c0d110c9c | third party advisory |