Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948 | third party advisory patch |
https://huntr.dev/bounties/075dbd51-b078-436c-9e3d-7f25cd2e7e1b | patch third party advisory exploit |