VDB
Sign up
MEDIUM4.3

GHSA-wqw3-p83g-r24v

Cross-Site Request Forgery in Spina

Details

A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272431. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/spina
Introduced in: 0

No fixed version published yet for spina (bundler). Pin to a known-safe version or switch to an alternative.

References