First published: Thu May 25 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
For The Badge | <=3.7.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41987 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with moderate severity.
To resolve CVE-2022-41987, update the BadgeOS plugin to version 3.7.1.7 or later.
CVE-2022-41987 affects BadgeOS plugin versions 3.7.1.6 and earlier.
CVE-2022-41987 can enable attackers to perform unwanted actions on behalf of authenticated users.
Yes, exploiting CVE-2022-41987 requires the attacker to trick an authenticated user into visiting a malicious link.