Gokapi CSRF Vulnerability in Login Flow
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. The issue arises because the login process accepts requests containing credentials without implementing CSRF protection linked to the browser session. The vulnerability allows for the direct parsing of form values, creating a session once the credentials are validated.
Impact
Exploitation of this vulnerability allows an attacker to trick a victim into logging into their account, potentially leading to confusion, misattribution of actions, and misuse of trusted user activities.
Remediation
Users are advised to update Gokapi to version 2.2.3 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
