VDB
Sign up
HIGH8.1

GHSA-ppq7-88c7-q879

Cross-Site Request Forgery in PiranhaCMS

Quick fix

GHSA-ppq7-88c7-q879 — Piranha: upgrade to the fixed version with the command below.

dotnet add package Piranha --version 10.0-alpha1

Details

In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Piranha
Introduced in: 4.0.0-alpha1Fixed in: 10.0-alpha1
Fixdotnet add package Piranha --version 10.0-alpha1

References