rdiffwen prior to version 2.4.7 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker can change a user’s email ID. Version 2.4.7 has a fix for this issue.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-3274
https://github.com/ikus060/…