Description
The console in Togglz before 2.9.4 allows CSRF.
Remediation
References
https://github.com/advisories/GHSA-697v-pxg3-j262
https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707
https://github.com/togglz/togglz/pull/495
Related Vulnerabilities
CVE-2022-2422 Vulnerability in npm package feathers-sequelize
CVE-2019-9512 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2018-1999007 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-28442 Vulnerability in maven package org.webjars.bower:js-data
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts