PT-2022-8883 · Togglz · Togglz

Joebeeton

·

Published

2022-07-15

·

Updated

2023-01-05

·

CVE-2020-28191

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Togglz versions prior to 2.9.4
Description The issue concerns the lack of CSRF protection in the Togglz console, which could allow an attacker to guess the CSRF token value. This lack of protection makes the console susceptible to Cross-Site Request Forgery attacks.
Recommendations For versions prior to 2.9.4, update to version 2.9.4 or later, which adds the necessary CSRF protection to the Togglz console.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-28191
GHSA-697V-PXG3-J262

Affected Products

Togglz