PT-2023-29269 · Wallabag · Wallabag

Published

2023-08-21

·

Updated

2023-08-24

·

CVE-2023-4454

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions wallabag versions prior to 2.6.3
Description The issue is related to Cross-Site Request Forgery (CSRF) in the wallabag GitHub repository. This allows attackers to arbitrarily reset annotations, entries, and tags by sending a GET request to specific API endpoints, such as "/reset/annotations", "/reset/entries", "/reset/tags", and "/reset/archived".
Recommendations For versions prior to 2.6.3, update to version 2.6.3 or higher, especially if you have more than one user and/or open registration. As a temporary workaround, consider restricting access to the vulnerable API endpoints until the update is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4454
GHSA-P8GP-899C-JVQ9
GHSA-RWPG-4C4C-V3R4

Affected Products

Wallabag