{"id":"CVE-2021-4005","aliases":["GHSA-hjhp-hwfj-hwf3"],"url":"https://o3.security/vulnerability/CVE-2021-4005","summary":"Cross Site Request Forgery in firefly-iii ","details":"firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)","published":"2021-12-04T12:15:07.377Z","modified":"2026-07-09T00:36:42.783337Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"grumpydictator/firefly-iii","fixedVersion":"5.6.5"}],"fix":{"url":"https://github.com/firefly-iii/firefly-iii/commit/03a1601bf343181df9f405dd2109aec483cb7053","label":"firefly-iii/firefly-iii@03a1601"},"references":[{"type":"FIX","url":"https://github.com/firefly-iii/firefly-iii/commit/03a1601bf343181df9f405dd2109aec483cb7053"},{"type":"FIX","url":"https://huntr.dev/bounties/bf4ef581-325a-492d-a710-14fcb53f00ff"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:36:42.783337Z"}}