PT-2026-24104 · Unknown · Sunbirded-Portal
Published
2026-03-09
·
Updated
2026-03-09
·
CVE-2025-70031
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SunbirdEd-portal version 1.13.4
Description
An issue related to Cross-Site Request Forgery (CSRF) was identified. CSRF attacks trick a user's browser into sending unwanted requests to a web application, potentially leading to unauthorized actions on behalf of the user.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider implementing CSRF protection mechanisms, such as synchronizer tokens, to validate requests.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunbirded-Portal