Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.
References
| Link | Resource |
|---|---|
| https://web.archive.org/web/20201109042653/https://github.com/salihciftci/liman | Product |
| https://www.exploit-db.com/exploits/48869 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/liman-cross-site-request-forgery-change-password | Third Party Advisory |
| https://www.exploit-db.com/exploits/48869 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-29 15:16
Updated : 2026-06-17 03:16
NVD link : CVE-2020-37007
Mitre link : CVE-2020-37007
CVE.ORG link : CVE-2020-37007
JSON object : View
Products Affected
salihciftci
- liman
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
