phpRedisAdmin cross-site request forgery
CVE-2021-4268

4.3MEDIUM

Key Information:

Vendor
CVE Published:
21 December 2022

What is CVE-2021-4268?

A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this issue. The name of the patch is b9039adbb264c81333328faa9575ecf8e0d2be94. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216471.

Affected Version(s)

phpRedisAdmin 1.14.0

phpRedisAdmin 1.14.1

phpRedisAdmin 1.15.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-4268 : phpRedisAdmin cross-site request forgery