CVE-2023-47350

HIGH

Swiftyedit < 1.2.0 - CSRF

Title source: rule

Description

Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

Scores

CVSS v3 8.8
EPSS 0.0068
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-352
Status published

Affected Products (2)

swiftyedit/swiftyedit < 1.2.0
swiftyedit/swiftyedit < 1.2.0Packagist

Timeline

Published Nov 22, 2023
Tracked Since Feb 18, 2026