QID 980102
QID 980102: Dotnet (nuget) Security Update for Piranha (GHSA-ppq7-88c7-q879)
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ppq7-88c7-q879 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ppq7-88c7-q879 -
github.com/advisories/GHSA-ppq7-88c7-q879
CVEs related to QID 980102
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ppq7-88c7-q879 | Piranha |
|