CVE-2023-37650: CSRF
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/cockpit-hq/cockpitto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Frequently Asked Questions
What is CVE-2023-37650?
CVE-2023-37650 is a Cross-Site Request Forgery (CSRF) vulnerability in the Admin portal of Cockpit CMS v2.5.2.
How does CVE-2023-37650 impact Cockpit CMS?
CVE-2023-37650 allows attackers to execute arbitrary Administrator commands in the Admin portal of Cockpit CMS v2.5.2.
What is the severity of CVE-2023-37650?
The severity of CVE-2023-37650 is high with a CVSS score of 8.8.
How can I fix CVE-2023-37650?
To fix CVE-2023-37650, upgrade Cockpit CMS to version 2.6.0 or later.
Where can I find more information about CVE-2023-37650?
You can find more information about CVE-2023-37650 at the following references: [link1](https://www.ghostccamm.com/blog/multi_cockpit_vulns/), [link2](https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.6.0), [link3](https://nvd.nist.gov/vuln/detail/CVE-2023-37650).