Description
The console in Togglz before 2.9.4 allows CSRF.
Remediation
References
https://github.com/advisories/GHSA-697v-pxg3-j262
https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707
https://github.com/togglz/togglz/pull/495
Related Vulnerabilities
CVE-2017-16183 Vulnerability in npm package iter-server
CVE-2019-5484 Vulnerability in npm package bower
CVE-2021-23392 Vulnerability in npm package locutus
CVE-2016-5018 Vulnerability in maven package org.apache.tomcat:tomcat-jasper
CVE-2020-2219 Vulnerability in maven package org.jenkins-ci.plugins:link-column