CVE-2021-37366

Publication date

2021-08-10 15:12:41

Family

mitre

State

PUBLISHED

Description

CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.