VDB
Sign up
HIGH8.8

GHSA-pq7f-cq6q-94xh

Cross-Site Request Forgery in Elefant CMS

Quick fix

GHSA-pq7f-cq6q-94xh — elefant/cms: upgrade to the fixed version with the command below.

composer require elefant/cms:^1.3.13

Details

A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/elefant/cms
Introduced in: 0Fixed in: 1.3.13
Fixcomposer require elefant/cms:^1.3.13

References