Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/3bbdafe6-e152-47bb-88a7-fd031725323d | exploit third party advisory patch |
https://github.com/squidex/squidex/commit/2da3c41da82eb945832f22bb70dba567ac6ce969 | third party advisory patch |