GHSA-8928-x2p4-43mrMediumCVSS 4.7

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in...

Published
August 29, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.

🔗 References (6)