A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
References
Link | Resource |
---|---|
https://gist.github.com/omriinbar-cyesec/c1179fe99725d2b828b6573c0d110c9c | Third Party Advisory |
https://getferdi.com/ | Product |
https://github.com/getferdi/ferdi | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-07-17 10:15
Updated : 2022-07-25 12:04
NVD link : CVE-2022-32320
Mitre link : CVE-2022-32320
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
getferdi
- ferdi
ferdium
- ferdium