Cross-Site Request Forgery in Musetheque by IPKNOWLEDGE
CVE-2026-28761

8.5HIGH

What is CVE-2026-28761?

A cross-site request forgery (CSRF) vulnerability has been identified in the Musetheque V4 application by IPKNOWLEDGE. If an authenticated user visits a malicious website, the attacker can potentially execute unauthorized actions on behalf of the user without their consent. This could lead to the disclosure of sensitive information or unintended actions taken against the user's account. It is crucial for users of affected versions, including V4 and V4L1 rev2203.0 or earlier, to be aware of this vulnerability and take necessary precautions, such as visiting only trusted sites while logged into their Musetheque accounts.

Affected Version(s)

Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.