HIGH
The console in Togglz before 2.9.4 allows CSRF
Published Dec 26, 2022
8.8
HIGHCVSS 3.1
EPSS 0.40%
Description
The console in Togglz before 2.9.4 allows CSRF.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6261 Advisory
- https://github.com/advisories/GHSA-697v-pxg3-j262 AdvisoryThird Party Advisory
- https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707 PatchThird Party Advisory
- https://github.com/togglz/togglz/pull/495 PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28191
- https://www.mend.io/vulnerability-database/CVE-2020-28191
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6261 | Advisory | |
| https://github.com/advisories/GHSA-697v-pxg3-j262 | AdvisoryThird Party Advisory | |
| https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707 | PatchThird Party Advisory | |
| https://github.com/togglz/togglz/pull/495 | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-28191 | ||
| https://www.mend.io/vulnerability-database/CVE-2020-28191 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2022
Updated Apr 14, 2025
Reserved Nov 2, 2020
Link CVE-2020-28191
CISA Vulnrichment
Updated Apr 14, 2025
ENISA EUVD
EUVD-2022-6261 GHSA-697V-PXG3-J262 Assigner mitre
Published Dec 26, 2022
Updated Apr 14, 2025
Exploited since n/a
Link EUVD-2022-6261