Sunbird-Ed SunbirdEd-portal Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Sunbird-Ed SunbirdEd-portal version 1.13.4. This issue allows attackers to deceive users into performing actions they did not intend to, potentially leading to unauthorized modifications of user data or account settings.

Impact

Exploitation of this vulnerability could result in unauthorized actions being performed on behalf of the user, potentially leading to changes in user data or account settings.

Reproduction

To reproduce this vulnerability, a user must be logged into the SunbirdEd portal. An attacker can then send a request that exploits the CSRF vulnerability, tricking the user into performing an action without their consent. This could be done by embedding the request in a web page or email that the user is likely to interact with.

Added: Mar 9, 2026, 8:18 PM
Updated: Mar 9, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.1
remediation
0.0
relevance
3.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.