What the vulnerability does
01Description
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
Explanation of Vulnerability in Simple Terms
Tribulant Newsletters versions up to 4.9.7 contain an input validation flaw that allows attackers to inject malicious content into the application. An attacker must trick a user into visiting a crafted link or page to exploit this vulnerability. The injected content can modify how the site displays information to that user, but cannot steal data or crash the site.
What an attacker can do
Inject malicious content that alters how the site displays to a victim who clicks a malicious link.
Potential impact on your site
Users visiting attacker-controlled links may see altered site content; no data breach or site outage risk.
Conditions required to exploit
Attacker must trick a user into clicking a link or visiting a page containing the malicious payload.
Key dates
External resources