CVE-2019-13183
07.07.2019, 15:15
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
Vendor | Product | Version |
---|---|---|
flarum | flarum | 0.1.0 |
flarum | flarum | 0.1.0:beta2 |
flarum | flarum | 0.1.0:beta3 |
flarum | flarum | 0.1.0:beta4 |
flarum | flarum | 0.1.0:beta5 |
flarum | flarum | 0.1.0:beta6 |
flarum | flarum | 0.1.0:beta7 |
flarum | flarum | 0.1.0:beta7.1 |
flarum | flarum | 0.1.0:beta7.2 |
flarum | flarum | 0.1.0:beta8 |
flarum | flarum | 0.1.0:beta8.1 |
flarum | flarum | 0.1.0:beta8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References