CVE-2023-5036: Cross-Site Request Forgery (CSRF) in usememos/memos
Published Sep 18, 2023
·Updated
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
Affected Software
2 affected componentsFixes available
go/github.com/usememos/memos<0.15.1
0.15.1
usememos memos<0.15.1
Remediation
Event History
Sep 18, 2023
CVE Published
via MITRE·05:46 AM
Data Sourced
via MITRE·05:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5036.
2
What is the severity of CVE-2023-5036?
The severity of CVE-2023-5036 is high.
3
Which software versions are affected by CVE-2023-5036?
The versions of GitHub repository usememos/memos prior to 0.15.1 are affected by CVE-2023-5036.
4
What is Cross-Site Request Forgery (CSRF)?
Cross-Site Request Forgery (CSRF) is a type of security vulnerability that allows an attacker to manipulate requests performed by a victim user in their web browser.
5
How do I fix CVE-2023-5036?
To fix CVE-2023-5036, update your GitHub repository usememos/memos to version 0.15.1 or higher.