Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/c9bb2b785dc5852655405d5c9ab127a2d5aa3948 | third party advisory patch |
https://huntr.dev/bounties/404ce7dd-f345-4d98-ad80-c53ac74f4e5c | exploit third party advisory patch |