What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery.This issue affects Make Paths Relative: from n/a through 1.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery.This issue affects Make Paths Relative: from n/a through 1.3.0.
Explanation of Vulnerability in Simple Terms
Make Paths Relative versions up to 1.3.0 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious link or page that, when visited by a logged-in user, performs unwanted actions on the site without the user's knowledge. The vulnerability requires user interaction—the victim must click a link or visit a page—but no special privileges.
What an attacker can do
Perform unwanted actions on the site by tricking a logged-in user into clicking a malicious link.
Potential impact on your site
Site users' actions can be hijacked to modify content, settings, or data without their consent.
Conditions required to exploit
A logged-in user must visit an attacker-controlled page or click a malicious link.
Key dates
External resources
Related vulnerabilities