CVE-2020-13868: CSRF
Published Jun 5, 2020
·Updated
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
Affected Software
2 affected componentsFixes available
composer/verbb/comments<1.5.5
1.5.5
verbb Comments Craft Cms<1.5.5
Event History
Jun 5, 2020
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13868?
CVE-2020-13868 has been classified as critical due to its impact on comment integrity through CSRF vulnerabilities.
2
How do I fix CVE-2020-13868?
To fix CVE-2020-13868, upgrade the Comments plugin to version 1.5.5 or later.
3
What software is affected by CVE-2020-13868?
CVE-2020-13868 affects versions of the Comments plugin for Craft CMS prior to 1.5.5.
4
What type of vulnerability is CVE-2020-13868?
CVE-2020-13868 is a cross-site request forgery (CSRF) vulnerability that compromises comment integrity.
5
Who is the vendor for CVE-2020-13868?
The vendor for CVE-2020-13868 is Verbb, the creator of the Comments plugin for Craft CMS.