Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948 | third party advisory patch |
https://huntr.dev/bounties/38c685fc-7065-472d-a46e-e26bf0b556d3 | patch third party advisory exploit |