First published: Tue Aug 24 2021(Updated: )
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Joplinapp Joplin | <2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-23431.
The severity of CVE-2021-23431 is high (8.8).
The affected software for CVE-2021-23431 is Joplin version up to exclusive 2.3.2.
CVE-2021-23431 is a vulnerability in Joplin that allows Cross-site Request Forgery (CSRF) attacks due to missing CSRF checks in various forms.
To fix CVE-2021-23431, update Joplin to version 2.3.2 or higher.