Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 PyPI

rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users

GHSA-cw2v-wv4g-w4p6 · CVE-2022-3232 · PYSEC-2022-281

Published · Modified

Description

rdiffweb prior to 2.4.5 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker exploiting this vulnerability can use it to delete repositories and users.

Ready to move

Start Securing

Free, no credit card | First findings in minutes