ended3월 17일· 1 sources
GHSA-WWG8-6FFR-H4Q2: GHSA-wwg8-6ffr-h4q2: Cross-Site Request Forgery in Admidio Role Management
Admidio 역할 관리 모듈의 CSRF(크로스 사이트 요청 위조) 취약점 (GHSA-wwg8-6ffr-h4q2)
Why it matters
Admidio versions 5.0.0 through 5.0.6 contain a CSRF vulnerability (CVSS 5.7) in the role management module, where missing anti-CSRF token validation allows attackers to delete or modify organizational roles by tricking authenticated administrators. A proof-of-concept exploit is available, and the issue is fixed in version 5.0.7.
1
Sources
+0
24h
—
Growth
178d
Active
AdmidioCSRFGHSA-wwg8-6ffr-h4q2Role ManagementCWE-352