PT-2019-13174 · Flarum · Flarum

Unknwncharlie

·

Published

2019-07-07

·

Updated

2019-07-09

·

CVE-2019-13183

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flarum versions prior to 0.1.0-beta.9
Description The issue allows for CSRF attacks against all POST endpoints. This can be demonstrated by changing admin settings.
Recommendations For versions prior to 0.1.0-beta.9, update to version 0.1.0-beta.9 or later to resolve the issue. As a temporary workaround, consider implementing CSRF protection measures to prevent unauthorized changes to admin settings.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13183
GHSA-3WJH-93GR-CHH6

Affected Products

Flarum