Description
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
Remediation
References
Related Vulnerabilities
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7061)
Plone CMS Missing Authentication for Critical Function Vulnerability (CVE-2020-35190)
qdPM Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-26180)
WordPress Plugin Polls CP Unspecified Vulnerability (1.0.17)