Lucene search

K
osvGoogleOSV:GHSA-3HQ4-F2V6-Q338
HistoryJul 12, 2018 - 8:30 p.m.

Kotti CSRF in the local roles implementation

2018-07-1220:30:30
Google
osv.dev
6

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.6%

Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.

Rows per page:
1-10 of 1031

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.6%

Related for OSV:GHSA-3HQ4-F2V6-Q338