What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1.
Explanation of Vulnerability in Simple Terms
Issuu Panel versions up to 2.1.1 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of a logged-in user. The vulnerability requires user interaction—the victim must visit a malicious page while authenticated to the panel. Successful exploitation can result in unauthorized changes to the panel's configuration or data.
What an attacker can do
Perform unauthorized actions on the Issuu Panel on behalf of a logged-in user.
Potential impact on your site
An attacker can modify panel settings or data if they trick an authenticated admin into visiting a malicious link.
Conditions required to exploit
Victim must be logged into Issuu Panel and visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities