Skip to content

[GHSA-r9vw-cjf9-xh4x] ProcessWire Cross Site Request Forgery vulnerability - #8928

Open
ryancramerdesign wants to merge 1 commit into
ryancramerdesign/advisory-improvement-8928from
ryancramerdesign-GHSA-r9vw-cjf9-xh4x
Open

[GHSA-r9vw-cjf9-xh4x] ProcessWire Cross Site Request Forgery vulnerability#8928
ryancramerdesign wants to merge 1 commit into
ryancramerdesign/advisory-improvement-8928from
ryancramerdesign-GHSA-r9vw-cjf9-xh4x

Conversation

@ryancramerdesign

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CWEs
  • Description
  • Summary

Comments
ProcessWire requests that this advisory be marked disputed or withdrawn. The authoritative CVE record was marked disputed by MITRE on July 9, 2026 and now includes the supplier’s rationale. The GitHub advisory still contains the superseded and inaccurate claim that this behavior permits arbitrary code execution. The affected endpoint intentionally accepts anonymous public comments, does not rely on visitor authentication or session authority, and holds submitted comments for moderation by default. This is longstanding, intentional CommentForm behavior and is not specific to version 3.0.229.

@github-actions
github-actions Bot changed the base branch from main to ryancramerdesign/advisory-improvement-8928 July 31, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant