HIGH8.8
GHSA-5v5q-3m7m-97j7
Image Resizer Cross-Site Request Forgery (CSRF)
Quick fix
GHSA-5v5q-3m7m-97j7 — verbb/image-resizer: upgrade to the fixed version with the command below.
composer require verbb/image-resizer:^2.0.9Details
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/verbb/image-resizer
Introduced in:
0Fixed in: 2.0.9Fix
composer require verbb/image-resizer:^2.0.9