CVE-2020-13458: CSRF
Published May 25, 2020
·Updated
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
Affected Software
2 affected componentsFixes available
verbb Image Resizer Craft Cms<2.0.9
composer/verbb/image-resizer<2.0.9
2.0.9
Event History
May 25, 2020
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13458?
CVE-2020-13458 is classified as a medium severity vulnerability due to its CSRF issues.
2
How do I fix CVE-2020-13458?
To fix CVE-2020-13458, update the Image Resizer plugin to version 2.0.9 or later.
3
What are the risks associated with CVE-2020-13458?
The risks associated with CVE-2020-13458 involve potential unauthorized actions being executed on behalf of authenticated users due to CSRF vulnerabilities.
4
Is CVE-2020-13458 exploitable remotely?
Yes, CVE-2020-13458 can be exploited remotely, as it involves CSRF vulnerabilities that can be triggered via malicious requests.
5
Which systems are affected by CVE-2020-13458?
CVE-2020-13458 affects versions of the Image Resizer plugin for Craft CMS prior to 2.0.9.