Headline
GHSA-9vxf-mcm6-5m42: rdiffweb CSRF could lead to disabling notifications in user profile
rdiffweb prior to 2.4.6 is vulnerable to Cross-Site Request Forgery (CSRF), which could lead to disabling notifications in a user’s profile.
rdiffweb CSRF could lead to disabling notifications in user profile
Moderate severity GitHub Reviewed Published Sep 22, 2022 • Updated Sep 22, 2022
Related news
CVE-2022-3233
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.