Back

LOW

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment

Published Jul 19, 2024

Description

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 19, 2024
Updated Jul 9, 2026
Reserved Jul 18, 2024
CISA Vulnrichment
Updated Jul 24, 2024
NVD
Status Modified
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Jul 19, 2024
Updated Jul 9, 2026
Exploited since n/a
EUVD-2024-2411 GHSA-R9VW-CJF9-XH4X