PT-2021-16900 · Unknown · Piranha Cms

Published

2021-11-16

·

Updated

2021-11-17

·

CVE-2021-25976

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PiranhaCMS versions 4.0.0-alpha1 through 9.2.0
Description The issue allows for cross-site request forgery (CSRF) when performing various actions supported by the management system. These actions include deleting a user, deleting a role, editing a post, and deleting a media folder, among others, when an ID is known.
Recommendations For PiranhaCMS versions 4.0.0-alpha1 through 9.2.0, consider implementing CSRF protection mechanisms, such as token-based validation, to prevent unauthorized actions. As a temporary workaround, restrict access to sensitive management system functions to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25976
GHSA-PPQ7-88C7-Q879

Affected Products

Piranha Cms