Vulnerabilities (CVE)

Filtered by vendor Save-server Project
Filtered by product Save-server
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15135 1 Save-server Project 1 Save-server 2024-11-21 6.8 MEDIUM 6.7 MEDIUM
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actio ...

Show More