PT-2022-21232 · Rdiffweb · Rdiffweb

Published

2022-09-21

·

Updated

2022-09-23

·

CVE-2022-3233

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.4.6
Description The issue is related to Cross-Site Request Forgery (CSRF) in the GitHub repository ikus060/rdiffweb. This could potentially lead to disabling notifications in a user's profile.
Recommendations For versions prior to 2.4.6, update to version 2.4.6 or later to resolve the issue.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3233
GHSA-9VXF-MCM6-5M42
PYSEC-2022-285

Affected Products

Rdiffweb