Impact
A security vulnerability was detected in birkir prime versions up to 0.4.0.beta.0 that allows attackers to exploit unprotected endpoints and trigger cross‑site request forgery. The flaw, identified as a missing or ineffective CSRF defense, permits remote actors to perform state‑changing actions on behalf of authenticated users, potentially compromising application integrity and user accounts.
Affected Systems
The vulnerability affects birkir prime installations where the software version is 0.4.0.beta.0 or earlier. No further version details are provided, and the issue is not limited to a specific configuration of the product.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, while the EPSS probability of less than 1% suggests exploitation is unlikely to be widespread at present. The vulnerability can be initiated remotely via the application’s exposed endpoints, and the publicly disclosed exploit could be weaponized against any unpatched deployment. The flaw is currently not listed in CISA’s KEV catalog, reflecting its limited exposure or lack of known exploitation incidents.
OpenCVE Enrichment