Spina gem vulnerable to Cross-site request forgery (CSRF) vulnerability
High severity
GitHub Reviewed
Published
Aug 28, 2018
to the GitHub Advisory Database
•
Updated Nov 4, 2023
Description
Published by the National Vulnerability Database
Sep 7, 2017
Published to the GitHub Advisory Database
Aug 28, 2018
Reviewed
Jun 16, 2020
Last updated
Nov 4, 2023
Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.
Spina::ApplicationController
actions didn't have CSRF protection. This causes a CSRF vulnerability across the entire engine which includes administrative functionality such as creating users, changing passwords, and media management.References