What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore by Stormhill Media allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore by Stormhill Media: from n/a through 3.3.4.
Explanation of Vulnerability in Simple Terms
02Summary
MyBookTable Bookstore by Stormhill Media versions up to 3.3.4 contain a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the bookstore without the admin's knowledge or consent. The vulnerability requires the victim to visit the attacker's page while authenticated.
What an attacker can do
03Attacker Capabilities
Perform unwanted actions on the bookstore (such as modifying settings or data) on behalf of a logged-in administrator.
Potential impact on your site
04Site Impact
An attacker can trick your administrators into unknowingly changing bookstore settings or data by visiting a crafted link.
Conditions required to exploit
05Prerequisites
A logged-in site administrator must visit a malicious webpage controlled by the attacker.
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated