Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19846
HistoryOct 31, 2021 - 12:00 a.m.

firefly-iii Cross-site Request Forgery Vulnerability (CNVD-2022-19846)

2021-10-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
8

0.001 Low

EPSS

Percentile

47.9%

firefly-iii is a free and open source personal finance software. firefly-iii suffers from a cross-site request forgery vulnerability, which originates when a WEB application does not sufficiently validate that a request is from a trusted user, and can be exploited by an attacker to send an unintended request to the server via the affected client.

0.001 Low

EPSS

Percentile

47.9%