Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.
References
| Link | Resource |
|---|---|
| https://web.archive.org/web/20201109042653/https://github.com/salihciftci/liman | Product |
| https://www.exploit-db.com/exploits/48869 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/liman-cross-site-request-forgery-change-password | Third Party Advisory |
| https://www.exploit-db.com/exploits/48869 | Exploit Third Party Advisory |
Configurations
History
17 Feb 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
13 Feb 2026, 20:24
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://web.archive.org/web/20201109042653/https://github.com/salihciftci/liman - Product | |
| References | () https://www.exploit-db.com/exploits/48869 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/liman-cross-site-request-forgery-change-password - Third Party Advisory | |
| CWE | CWE-352 | |
| First Time |
Salihciftci liman
Salihciftci |
|
| CPE | cpe:2.3:a:salihciftci:liman:0.7:*:*:*:*:*:*:* |
29 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/48869 - |
29 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-29 15:16
Updated : 2026-02-17 13:16
NVD link : CVE-2020-37007
Mitre link : CVE-2020-37007
CVE.ORG link : CVE-2020-37007
JSON object : View
Products Affected
salihciftci
- liman
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
