PT-2026-83448 · Rodauth · Rodauth
CVSS v4.0
4.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rodauth versions prior to 2.47.0
Description
An issue exists in the JSON request content type validation that allows a cross-site request forgery (CSRF) protection bypass. CSRF is a type of attack that tricks a victim into submitting a malicious request. Attackers can craft cross-origin form posts with content types containing
application/json substrings to bypass token validation, potentially forcing victims to authenticate to accounts controlled by the attacker.Recommendations
Update to version 2.47.0 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rodauth