ended3월 17일· 1 sources

GHSA-WWG8-6FFR-H4Q2: GHSA-wwg8-6ffr-h4q2: Cross-Site Request Forgery in Admidio Role Management

Admidio 역할 관리 모듈의 CSRF(크로스 사이트 요청 위조) 취약점 (GHSA-wwg8-6ffr-h4q2)

Why it matters

Admidio versions 5.0.0 through 5.0.6 contain a CSRF vulnerability (CVSS 5.7) in the role management module, where missing anti-CSRF token validation allows attackers to delete or modify organizational roles by tricking authenticated administrators. A proof-of-concept exploit is available, and the issue is fixed in version 5.0.7.

1
Sources
+0
24h
Growth
178d
Active
AdmidioCSRFGHSA-wwg8-6ffr-h4q2Role ManagementCWE-352

Sources

Related Issues