CVE-2021-25976
Dashboard / Vulnerabilities / CVE-2021-25976
Summary:
Details: In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
References: https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25976, https://github.com/PiranhaCMS/piranha.core/commit/e42abacdd0dd880ce9cf6607efcc24646ac82eda
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- c5b65aad9762e144bb9adfad317fa34b7dcf97b6
Fixed -None
Affected versions
4.0.0-NA
4.0.0-alpha1
4.0.0-alpha3
4.0.0-alpha4
4.0.0-alpha5
4.0.0-alpha6
4.0.0-alpha7
4.0.0-alpha8
4.0.0-alpha9
4.0.0-beta1
4.0.0-rc1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
