CVE-2023-32625

Medium
|4.3
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to take control of a user's account and change their settings by tricking them into visiting a malicious webpage. The attacker does not need to be logged in, but the user must be authenticated and visit the harmful page while logged into the affected application.

Technical Description

Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactNone
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$552($500-$1K)
Vendor Response
Grade FPatched in 971 days

Quick Information

Published

Jul 21, 2023

over 2 years ago

Last Modified

Mar 18, 2026

20 days ago

Vendor

sakura

Product

ts webfonts for sakura