Description
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 10.0.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2374 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known. |
Github GHSA |
GHSA-ppq7-88c7-q879 | Cross-Site Request Forgery in PiranhaCMS |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:46:50.534Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25976
Updated: 2024-08-03T20:19:19.376Z
Status : Modified
Published: 2021-11-16T09:15:06.717
Modified: 2024-11-21T05:55:42.930
Link: CVE-2021-25976
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA