Cross-site Request Forgery (CSRF) Affecting nodebb-plugin-blog-comments package, versions <0.7.0
Threat Intelligence
EPSS
0.08% (37th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-NODEBBPLUGINBLOGCOMMENTS-1053246
- published 21 Dec 2020
- disclosed 20 Dec 2020
- credit Artur Matczak
Introduced: 20 Dec 2020
CVE-2020-15156 Open this link in a new tabHow to fix?
Upgrade nodebb-plugin-blog-comments
to version 0.7.0 or higher.
Overview
nodebb-plugin-blog-comments is a NodeBB Blog Comments (Ghost / WP Commenting Engine)
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). A logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum, due to lack of CSRF validation.
References
CVSS Scores
version 3.1