Skip to content

CSRF in backup page

High
piRGoif published GHSA-34rq-vfmf-gg5v Sep 18, 2020

Package

No package listed

Affected versions

<2.7.1, < 3.0.0

Patched versions

2.7.1, 3.0.0

Description

Impact

A CSRF can be possible in backup ajax page.

Patches

  • 2.7.1 : packages community, essential, professional
  • 3.0.0 : to be published

Credits

Many thanks to TW/CERT for his report !

References

Combodo ref N°2985
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12781

For more information

If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com

Severity

High

CVE ID

CVE-2020-12781

Weaknesses

No CWEs