CVE-2023-27160 - Cross Site Request Forgery (CSRF) Description forem up to v2022.11.11 was discovered to contain a Cross Site Request Forgery (CSRF) via the component . Vulnerability Type Cross Site Request Forgery (CSRF) Vendor of Product https://github.com/forem/forem Affected Product Code Base forem - <= Version 2022.11.11 Affected Component The API endpoints are vulnerable to CSRF attacks via the parameter. Attack Type Remote Impact Code execution true Impact Escalation of Privileges true Impact Information Disclosure true Attack Vectors POC: POST API with details can be seen: https://notes.sjtu.edu.cn/s/EEEK9r_Gw Discoverer beetie Reference http://forem.com https://github.com/forem/forem https://notes.sjtu.edu.cn/s/EEEK9r_Gw