CVE-2023-47350

HIGH

Swiftyedit < 1.2.0 - CSRF

Title source: rule
STIX 2.1

Description

Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

Scores

CVSS v3 8.8
EPSS 0.0068
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Products (2)
swiftyedit/swiftyedit < 1.2.0
swiftyedit/swiftyedit 0 - 1.2.0Packagist
Published Nov 22, 2023
Tracked Since Feb 18, 2026