PT-2023-7576 · Unknown · Sticky Notes App Using Php With Source Code
Emirhanerdogu
·
Published
2023-11-22
·
Updated
2023-12-04
·
CVE-2023-47014
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sticky Notes App Using PHP with Source Code version 1.0
Description
The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability. This vulnerability can be exploited by a remote attacker to gain access to confidential information. The exploitation involves sending a crafted payload to the
add-note.php endpoint, allowing the attacker to obtain sensitive information.Recommendations
For Sticky Notes App Using PHP with Source Code version 1.0, consider disabling access to the
add-note.php endpoint until a patch is available to prevent exploitation of the CSRF vulnerability. Restricting access to this endpoint can help minimize the risk of sensitive information being obtained by an attacker.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sticky Notes App Using Php With Source Code