SA-2023-104 - Chalet cross-site request forgery (CVE-2023-43118)
Summary Endpoints of the Chalet application are vulnerable to CSRF allowing a cross-domain request to force an authenticated user to perform actions. This includes the /jsonrpc API which can force an ...