CLICK ME! Impact This vulnerability is capable of tricking users to disable 2FA.">Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii - vulnerability database | Vulners.comCLICK ME! Impact This vulnerability is capable of tricking users to disable 2FA.">CLICK ME! Impact This vulnerability is capable of tricking users to disable 2FA.">CLICK ME! Impact This vulnerability is capable of tricking users to disable 2FA.">
Lucene search

K
huntrHaxatronBF4EF581-325A-492D-A710-14FCB53F00FF
HistoryNov 23, 2021 - 9:11 a.m.

Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii

2021-11-2309:11:35
haxatron
www.huntr.dev
6

0.001 Low

EPSS

Percentile

30.0%

Description

CSRF to disable 2FA

Proof of Concept

<a href="http://10.0.2.15/profile/delete-code">CLICK ME!</a>

Impact

This vulnerability is capable of tricking users to disable 2FA.

0.001 Low

EPSS

Percentile

30.0%

Related for BF4EF581-325A-492D-A710-14FCB53F00FF