PT-2023-27304 · Unknown · Social Media Skeleton
Zodiac0704
·
Published
2023-08-18
·
Updated
2023-08-23
·
CVE-2023-40172
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Social media skeleton versions prior to 1.0.5
Description
A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done by sending the victim a malicious link or by exploiting a vulnerability in the website. The Social media skeleton project did not properly restrict CSRF attacks prior to version 1.0.5.
Recommendations
For versions prior to 1.0.5, upgrade to version 1.0.5 to address the CSRF vulnerability. As a temporary workaround, consider implementing additional security measures to restrict malicious requests, but it is advised to upgrade as soon as possible since there are no known workarounds for this vulnerability.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Social Media Skeleton