CVE-2023-0737: CSRF in wallabag/wallabag
Published Nov 15, 2024
·Updated
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.
Affected Software
2 affected componentsFixes available
composer/wallabag/wallabag<2.5.4
2.5.4
wallabag wallabag=2.5.2
Remediation
Event History
Nov 15, 2024
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-0737?
CVE-2023-0737 is considered a high severity vulnerability due to its potential for account deletion via CSRF.
2
How do I fix CVE-2023-0737?
To fix CVE-2023-0737, upgrade Wallabag to version 2.5.4 or later.
3
What versions of Wallabag are affected by CVE-2023-0737?
Wallabag version 2.5.2 is affected by CVE-2023-0737.
4
What type of vulnerability is CVE-2023-0737?
CVE-2023-0737 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Where can I find more details about CVE-2023-0737?
Details about CVE-2023-0737 can typically be found in security advisories and vulnerability databases.