CVE-2018-9856
09.04.2018, 07:29
Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.
Vendor | Product | Version |
---|---|---|
kotti_project | kotti | 𝑥 < 1.3.2 |
kotti_project | kotti | 2.0.0:alpha1 |
kotti_project | kotti | 2.0.0b1:b1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration