CVE-2021-45017
15.12.2021, 23:15
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.
Vendor | Product | Version |
---|---|---|
catfish-cms | catfish_cms | 𝑥 ≤ 6.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration