Impact
A Cross‑Site Request Forgery flaw exists within Squidex CMS’s IdentityServer account profile endpoint, allowing a remote attacker to exploit an authenticated user’s session and elevate privileges. Because the endpoint accepts state‑changing requests without an anti‑forgery token, malicious actors can tamper with account settings or assign themselves administrative roles, directly compromising system integrity.
Affected Systems
The vulnerability impacts Squidex CMS versions 7.21.0 and all earlier releases, specifically targeting the IdentityServer component. No other vendors or products are listed as affected.
Risk and Exploitability
The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, but the CSRF nature coupled with privilege escalation capability suggests a significant exploitation likelihood against authenticated users. The CVSS score of 6.5 indicates medium severity. In the absence of a public patch, the risk remains high until the software is updated or mitigated with additional controls.
OpenCVE Enrichment