Vulnerabilities > CVE-2021-3901 - Unspecified vulnerability in Firefly-Iii Firefly III
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Vulnerable Configurations
References
- https://github.com/firefly-iii/firefly-iii/commit/b42d8d1e305cad70d9b83b33cd8e0d7a4b2060c2
- https://github.com/firefly-iii/firefly-iii/commit/b42d8d1e305cad70d9b83b33cd8e0d7a4b2060c2
- https://huntr.dev/bounties/62508fdc-c26b-4312-bf75-fd3a3f997464
- https://huntr.dev/bounties/62508fdc-c26b-4312-bf75-fd3a3f997464