What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Tumult Inc Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Tumult Inc Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.11.
Explanation of Vulnerability in Simple Terms
Tumult Hype Animations versions up to 1.9.11 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can trick a user into performing unwanted actions on a site running the affected component by crafting a malicious link or page. The vulnerability requires user interaction—the victim must click a link or visit a page—and affects only the integrity of data, not confidentiality or availability.
What an attacker can do
Trick a user into performing unwanted actions on a site running the affected component.
Potential impact on your site
Users' actions (such as form submissions) can be forged by attackers without the users' knowledge or consent.
Conditions required to exploit
The victim must click a malicious link or visit an attacker-controlled page while logged in.
Key dates
External resources
Related vulnerabilities