Description
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/efb93f1f-1896-4a4c-a059-9ecadac1c4de
Patch, Third Party Advisory x_refsource_misc
https://github.com/crater-invoice/crater/commit/2b7028b7c83fd6e8897f244a2e6723baa20479e5
Scores
CVSS v3
4.3
EPSS
0.0042
EPSS Percentile
33.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-352
Status
published
Products (1)
craterapp/crater
< 6.0.4
Published
Mar 21, 2022
Tracked Since
Feb 18, 2026