CVE-2021-25976
16.11.2021, 09:15
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
Vendor | Product | Version |
---|---|---|
dotnetfoundation | piranha_cms | 4.0.1 ≤ 𝑥 ≤ 9.2 |
dotnetfoundation | piranha_cms | 4.0.0 |
dotnetfoundation | piranha_cms | 4.0.0:alpha1 |
dotnetfoundation | piranha_cms | 4.0.0:alpha3 |
dotnetfoundation | piranha_cms | 4.0.0:alpha4 |
dotnetfoundation | piranha_cms | 4.0.0:alpha5 |
dotnetfoundation | piranha_cms | 4.0.0:alpha6 |
dotnetfoundation | piranha_cms | 4.0.0:alpha7 |
dotnetfoundation | piranha_cms | 4.0.0:alpha8 |
dotnetfoundation | piranha_cms | 4.0.0:alpha9 |
dotnetfoundation | piranha_cms | 4.0.0:beta1 |
dotnetfoundation | piranha_cms | 4.0.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References