What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in benmoreassynt DancePress (TRWA) dancepress-trwa allows Cross Site Request Forgery.This issue affects DancePress (TRWA): from n/a through <= 3.1.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in benmoreassynt DancePress (TRWA) dancepress-trwa allows Cross Site Request Forgery.This issue affects DancePress (TRWA): from n/a through <= 3.1.11.
Explanation of Vulnerability in Simple Terms
DancePress versions up to 3.1.11 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted actions on behalf of a logged-in user. The vulnerability requires user interaction—the victim must visit a malicious page while authenticated. The impact is limited to denial of service through resource exhaustion or temporary unavailability.
What an attacker can do
Perform unwanted actions on behalf of a logged-in user, such as triggering resource-intensive operations.
Potential impact on your site
Users' authenticated sessions can be abused to perform unintended actions; site availability may be affected.
Conditions required to exploit
Victim must be logged into DancePress and visit an attacker-controlled page or link.
Key dates
External resources
Related vulnerabilities