CVE-2021-46366

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
11/02/2022
Last modified:
12/07/2022

Description

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:magnolia-cms:magnolia_cms:*:*:*:*:*:*:*:* 6.2.4 (excluding)