Description
A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.
Exploits (1)
nomisec
WRITEUP
1 stars
by emirhanerdogu · poc
https://github.com/emirhanerdogu/CVE-2023-47014-Sticky-Notes-App-Using-PHP-with-Source-Code-v1.0-CSRF-to-CORS
References (1)
Core 1
Core References
Scores
CVSS v3
6.5
EPSS
0.0011
EPSS Percentile
28.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-352
Status
published
Products (1)
remyandrade/sticky_notes_app
1.0
Published
Nov 22, 2023
Tracked Since
Feb 18, 2026