Cross-Site Request Forgery Vulnerability in SourceCodester Note Taking App
CVE-2026-4971
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 27 March 2026
Badges
What is CVE-2026-4971?
A security vulnerability has been discovered in SourceCodester Note Taking App version 1.0, allowing attackers to perform unauthorized actions on behalf of users through cross-site request forgery. This vulnerability can be exploited remotely, putting users at risk without their knowledge. Attackers can leverage this weakness to carry out malicious activities, highlighting the need for prompt updates and security measures to safeguard sensitive data.
Affected Version(s)
Note Taking App 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
