< ciso
brief />
Tag Banner

All news with #cross site request forgery tag

9 articles

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A CSRF vulnerability in the Elementor WordPress plugin could let an unauthenticated attacker create administrator accounts by tricking a logged-in admin into opening a crafted link. The flaw affects versions 4.3.0 and 4.3.1, which are active on up to 2 million sites. Patchstack reported the issue to Elementor on September 22 and a fix was issued in version 4.3.2 two days later. Users are advised to update immediately to prevent one-click admin account creation attacks.
read more →

WordPress Click2Shell flaw enables remote PHP execution

🛡️ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.
read more →

Critical AgentForger Flaw in ChatGPT Workspace Agents

🛡️ Cybersecurity researchers disclosed a critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. The flaw—an instance of cross-site request forgery—let an attacker embed an executable prompt in a URL that auto-executes when clicked by an authenticated user with Workspace Agents and connectors. OpenAI patched the issue on June 8, 2026, and has deprecated the Agent Builder, urging a migration to the Agents SDK.
read more →

OpenPLC_V3 CSRF Vulnerability Allows Remote Changes

⚠ OpenPLC_V3 contains a Cross‑Site Request Forgery (CSRF) vulnerability that can be exploited remotely to modify PLC settings or upload malicious programs. Tracked as CVE-2025-13970, the issue affects versions prior to pull request #310 and results from missing CSRF validation. A CVSS v4 score of 7.0 (and v3 base 8.0) was calculated. Apply pull request #310 or later to mitigate this risk and limit network exposure of control devices.
read more →

Siemens SICAM P850/P855: CSRF and Session Token Flaws

🔒 Siemens reported Cross-Site Request Forgery and incorrect permission assignment vulnerabilities affecting SICAM P850 and P855 devices (versions prior to 3.11). Exploitation could allow attackers to perform actions as authenticated users or impersonate sessions. Siemens recommends updating to v3.11+, restricting TCP/443 to trusted IPs, and hardening network access; CISA advises isolating control networks and avoiding internet exposure.
read more →

Atlas browser CSRF flaw lets attackers poison ChatGPT memory

⚠️ Researchers at LayerX disclosed a vulnerability in ChatGPT Atlas that can let attackers inject hidden instructions into a user's memory via a CSRF vector, contaminating stored context and persisting across sessions and devices. The exploit works by tricking an authenticated user to visit a malicious page which issues a CSRF request to silently write memory entries that later influence assistant responses. Detection requires behavioral hunting—correlating browser logs, exported chats and timestamped memory changes—since there are no file-based indicators. Administrators are advised to limit Atlas in enterprise pilots, export and review chat histories, and treat affected accounts as compromised until memory is cleared and credentials rotated.
read more →

ChatGPT Atlas 'Tainted Memories' CSRF Risk Exposes Accounts

⚠️ Researchers disclosed a CSRF-based vulnerability in ChatGPT Atlas that can inject malicious instructions into the assistant's persistent memory, potentially enabling arbitrary code execution, account takeover, or malware deployment. LayerX warns that corrupted memories persist across devices and sessions until manually deleted and that Atlas' anti-phishing defenses lag mainstream browsers. The flaw converts a convenience feature into a persistent attack vector that can be invoked during normal prompts.
read more →

Understanding Cookie Types and How to Protect Them

🔒 This article explains how web cookies work, their classifications, and why session IDs are particularly valuable to attackers. It outlines common attack methods — including session sniffing over HTTP, cross‑site scripting (XSS), cross‑site request forgery (CSRF), and predictable session IDs — and describes specialized tracking like supercookies and evercookies. Practical advice for users and developers covers HTTPS, browser updates, cookie management, two‑factor authentication, cautious use of public Wi‑Fi, and preferring essential cookies only.
read more →