Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/d7007f76-3dbc-48a7-a2fb-377040fe100c | exploit third party advisory patch |
https://github.com/modoboa/modoboa/commit/7f0573e917227686d2cc127be1364e2908740807 | third party advisory patch |