HIGH8.1
GHSA-ppq7-88c7-q879
Cross-Site Request Forgery in PiranhaCMS
Quick fix
GHSA-ppq7-88c7-q879 — Piranha: upgrade to the fixed version with the command below.
dotnet add package Piranha --version 10.0-alpha1Details
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Piranha
Introduced in:
4.0.0-alpha1Fixed in: 10.0-alpha1Fix
dotnet add package Piranha --version 10.0-alpha1