What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful performance-based content: from n/a through 2.1.20.
Explanation of Vulnerability in Simple Terms
02Summary
This page builder contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of a logged-in user. An attacker can craft a malicious link or page that, when visited by a site administrator, triggers unintended changes to the site's content or settings. The vulnerability requires user interaction—the admin must click the link or visit the attacker's page while logged in.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into performing unwanted actions on the site, such as modifying pages or settings.
Potential impact on your site
04Site Impact
An attacker can modify your site's content or configuration if they trick you into clicking a link while logged in.
Conditions required to exploit
05Prerequisites
The site admin must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
06Disclosure timeline
February 28, 2024
CVE published
April 28, 2026
Record updated