Description
Cross-Site Request Forgery (CSRF) vulnerability in Kaloyan K. Tsvetkov Broken Images allows Cross-Site Scripting (XSS).This issue affects Broken Images: from n/a through 0.2.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version
Credits
Dimas Maulana (Patchstack Alliance)
References
patchstack.com/...in-0-2-csrf-to-xss-vulnerability?_s_id=cve