Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/46881df7-eb41-4ce2-a78f-82de9bc4fc2d | patch third party advisory exploit |
https://github.com/usememos/memos/commit/97b434722cf0abe3cfcad5ac9e3d520233bf1536 | patch |