daylightstudio / FUEL-CMS

A CodeIgniter Content Management System
http://www.getfuelcms.com
1.02k stars 453 forks source link

FUEL-CMS V1.4.13 Cross-site request forgery (CSRF) vulnerability #576

Closed yyymmm1211 closed 3 years ago

yyymmm1211 commented 4 years ago

In /pages/delete/3 Cross-site request forgery (CSRF) vulnerability The Attacker can use this vulnerability to delete random pages!

222png

POC: 111