Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33179
HistoryDec 06, 2021 - 3:44 a.m.

Cross-site Request Forgery (CSRF)

2021-12-0603:44:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
cross-site request forgery
csrf
user validation
email confirmation
duplicate username
account access

EPSS

0.001

Percentile

41.1%

ssddanbrown/bookstack is vulnerable to cross-site request forgery attacks. The library does not properly validate the user login flow after the email confirmation, allowing an attacker to duplicate the username and gain access to the account when user click the confirmation link.

EPSS

0.001

Percentile

41.1%