CVE-2019-13183
07.07.2019, 15:15
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
| Vendor | Product | Version |
|---|---|---|
| flarum | flarum | 0.1.0 |
| flarum | flarum | 0.1.0:beta2 |
| flarum | flarum | 0.1.0:beta3 |
| flarum | flarum | 0.1.0:beta4 |
| flarum | flarum | 0.1.0:beta5 |
| flarum | flarum | 0.1.0:beta6 |
| flarum | flarum | 0.1.0:beta7 |
| flarum | flarum | 0.1.0:beta7.1 |
| flarum | flarum | 0.1.0:beta7.2 |
| flarum | flarum | 0.1.0:beta8 |
| flarum | flarum | 0.1.0:beta8.1 |
| flarum | flarum | 0.1.0:beta8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References