flexocms / flexo1.source

Flexo CMS.
http://flexocms.github.io/flexo1.source/
7 stars 4 forks source link

There is a CSRF vulnerability that can add an administrator #25

Open riyir opened 6 years ago

riyir commented 6 years ago
jmas commented 6 years ago

Hello, @riyir, Flexo CMS development currently is frozen. Thank you for letting us know about CSRF vulnerability. Flexo CMS do not support CSRF validation at the moment. And I do not have any estimation about when it will be added. If you have some time to write working solution for that (as part of core functionality or as plugin) - I will review and accept your PR to Flexo CMS repository. Thank you and good luck!