PT-2023-27304 · Unknown · Social Media Skeleton
Zodiac0704
·
Publicado
2023-08-18
·
Atualizado
2023-08-23
·
CVE-2023-40172
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Social media skeleton versions prior to 1.0.5
Description
A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done by sending the victim a malicious link or by exploiting a vulnerability in the website. The Social media skeleton project did not properly restrict CSRF attacks prior to version 1.0.5.
Recommendations
For versions prior to 1.0.5, upgrade to version 1.0.5 to address the CSRF vulnerability. As a temporary workaround, consider implementing additional security measures to restrict malicious requests, but it is advised to upgrade as soon as possible since there are no known workarounds for this vulnerability.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Social Media Skeleton