CVE-2023-27295
28.02.2023, 17:15
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating a dummy page that executes Javascript in an authenticated user's session when visited.
Vendor | Product | Version |
---|---|---|
opencats | opencats | 0.9.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration