Cross-Site Request Forgery in BloofoxCMS 0.5.2.1
CVE-2020-36140
6.5MEDIUM
What is CVE-2020-36140?
BloofoxCMS version 0.5.2.1 is susceptible to Cross-Site Request Forgery (CSRF), which allows attackers to perform unauthorized actions on behalf of a user. Specifically, an attacker may exploit the 'mode=settings&page=editor' functionality to alter file content both locally and remotely. This security flaw poses a significant risk to users by enabling potential data manipulation without proper authentication.
