Cross-Site Request Forgery Vulnerability in FUEL CMS by Daylight Studio
CVE-2020-28705

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 March 2021

What is CVE-2020-28705?

FUEL CMS version 1.4.13 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. An attacker can exploit this security flaw to delete a specific page by sending a specially crafted request containing the page's post ID to the '/pages/delete/3' endpoint. This vulnerability could result in unauthorized modifications to website content, highlighting the need for robust security measures to protect user data and website integrity.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.