Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-29 15:16
Updated : 2026-01-29 17:16
NVD link : CVE-2020-37007
Mitre link : CVE-2020-37007
CVE.ORG link : CVE-2020-37007
JSON object : View
Products Affected
No product.
CWE
CWE-565
Reliance on Cookies without Validation and Integrity Checking
