Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-03911
HistoryDec 04, 2021 - 12:00 a.m.

bookstack cross-site request forgery vulnerability

2021-12-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
bookstackapp cross-site request forgery validation

EPSS

0.001

Percentile

41.1%

BookStack is the BookStackApp team’s open source platform for building wiki documents using PHP and Laravel. bookstack suffers from a cross-site request forgery vulnerability, which stems from the software’s lack of validation for cross-site request forgery. An attacker could use this vulnerability to spoof malicious requests to trick victims into clicking through to perform sensitive actions.

EPSS

0.001

Percentile

41.1%