
Cloud Vulnerability DB
A community-led vulnerabilities database
Showdoc, a documentation platform, was found to be vulnerable to Cross-Site Request Forgery (CSRF) attacks, identified as CVE-2021-4168. The vulnerability was discovered and disclosed in December 2021 (CVE Details).
The vulnerability stems from insufficient CSRF protection mechanisms in various controller endpoints of the Showdoc application. The issue affected multiple API controllers including AdminItem, AdminUser, Catalog, Item, ItemGroup, ItemVariable, Member, Page, Team, and TeamMember controllers. The vulnerability allowed attackers to perform unauthorized actions by tricking authenticated users into executing unwanted commands (GitHub Commit).
If exploited, this CSRF vulnerability could allow attackers to perform unauthorized actions on behalf of authenticated users, potentially leading to unauthorized modifications of documentation, user management changes, and other administrative actions without the user's consent or knowledge (Huntr Report).
The issue was addressed through a security update that modified the application to properly validate request methods and implement CSRF protection. The fix involved updating multiple controller endpoints to specifically check for POST requests and implement proper request validation (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."