ZeroHour

CVE-2019-20077

CVSS 3.1
4.3 medium
EPSS
<1%p34
Published
()
Modified
Description

The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.

Vendors
typesettercms
Products
typesetter
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.