CVE-2021-46366: CSRF
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46366?
CVE-2021-46366 is considered a high severity vulnerability due to its potential for credential exfiltration and exploitation by attackers.
How do I fix CVE-2021-46366?
To remediate CVE-2021-46366, upgrade Magnolia CMS to version 6.2.4 or later, which addresses the identified vulnerabilities.
What types of vulnerabilities are present in CVE-2021-46366?
CVE-2021-46366 includes an Open Redirect vulnerability and a Cross-Site Request Forgery (CSRF) vulnerability.
How can CVE-2021-46366 affect my organization?
CVE-2021-46366 can allow attackers to perform brute force attacks on user credentials, potentially leading to unauthorized access to sensitive information.
Which versions of Magnolia CMS are affected by CVE-2021-46366?
CVE-2021-46366 affects Magnolia CMS version 6.2.3 and below.