VDB
Sign up
HIGH8.8

GHSA-79m2-h67v-35q7

Elefant CMS CSRF Vulnerability

Quick fix

GHSA-79m2-h67v-35q7 — elefant/cms: upgrade to the fixed version with the command below.

composer require elefant/cms:^2.0.5

Details

An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/elefant/cms
Introduced in: 0Fixed in: 2.0.5
Fixcomposer require elefant/cms:^2.0.5

References