CVE-2023-0735: Cross-Site Request Forgery (CSRF) in wallabag/wallabag
Published Feb 7, 2023
·Updated
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.
Affected Software
1 affected component
wallabag wallabag<2.5.4
Remediation
Event History
Feb 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0735?
CVE-2023-0735 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting versions of Wallabag prior to 2.5.4.
2
How do I fix CVE-2023-0735?
To fix CVE-2023-0735, upgrade Wallabag to version 2.5.4 or later.
3
What systems are affected by CVE-2023-0735?
CVE-2023-0735 affects all versions of Wallabag before 2.5.4.
4
Can CVE-2023-0735 lead to unauthorized actions?
Yes, due to CSRF, CVE-2023-0735 can allow attackers to perform unauthorized actions on behalf of users.
5
When was CVE-2023-0735 published?
CVE-2023-0735 was published in early 2023.