Vulnerability Details CVE-2023-32625
Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.0%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-32625
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:-
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:0.9.0
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.0
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.1
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.2
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.3
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.4
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:1.0.5
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:2.0.0
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:2.0.1
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:3.0.0
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:3.1.0
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:3.1.1
-
cpe:2.3:a:sakura:ts_webfonts_for_sakura:3.1.2