A critical vulnerability was discovered in React Server Components (Next.js). Our systems remain protected but we advise to update packages to newest version. Learn More

Form Export could be done without valid CSRF token

Found in

EPiServer.Forms 5.5.1

Fixed in

EPiServer.Forms 5.6.0

(Or a related package)

Created

Apr 14, 2023

Updated

Jul 01, 2025

State

Closed, Fixed and tested


Description

Fixed an issue where exporting a form executed without a valid CSRF token.