CSRF Vulnerability in Comments Plugin for Craft CMS by Verbb
CVE-2020-13868

6.5MEDIUM

Key Information:

Vendor

Verbb

Status
Vendor
CVE Published:
5 June 2020

What is CVE-2020-13868?

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Comments plugin for Craft CMS prior to version 1.5.5. This security issue can compromise comment integrity, allowing attackers to manipulate or abuse comment functionality without the user's consent. It underscores the importance of ensuring security measures are in place to protect against such vulnerabilities.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.