Vulnerabilities > CVE-2021-4005 - Unspecified vulnerability in Firefly-Iii Firefly III
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Vulnerable Configurations
References
- https://github.com/firefly-iii/firefly-iii/commit/03a1601bf343181df9f405dd2109aec483cb7053
- https://github.com/firefly-iii/firefly-iii/commit/03a1601bf343181df9f405dd2109aec483cb7053
- https://huntr.dev/bounties/bf4ef581-325a-492d-a710-14fcb53f00ff
- https://huntr.dev/bounties/bf4ef581-325a-492d-a710-14fcb53f00ff