October CMS CSRF
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 3, 2023
Description
Published by the National Vulnerability Database
Nov 1, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 25, 2023
Last updated
Oct 3, 2023
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.
References