RubySec

Providing security resources for the Ruby community

CVE-2024-7106 (spina): Cross-Site Request Forgery in Spina

ADVISORIES

GEM

spina

SEVERITY

CVSS v3.x: 4.3 (Medium)

CVSS v2.0: 5.0 (Medium)

PATCHED VERSIONS

None.

DESCRIPTION

A vulnerability classified as problematic was found in Spina CMS 2.18.0.

Affected by this vulnerability is an unknown functionality of the file /admin/media_folders.

The manipulation leads to cross-site request forgery. The attack can be launched remotely.

The exploit has been disclosed to the public and may be used.

The associated identifier of this vulnerability is VDB-272431.

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

RELATED