Cross Site Request Forgery in FUEL-CMS by Daylight Studio
CVE-2021-36569
8.8HIGH
What is CVE-2021-36569?
FUEL-CMS version 1.4.13 is susceptible to a Cross Site Request Forgery (CSRF) vulnerability that permits remote attackers to execute arbitrary code by manipulating a POST request to the /users/delete/2 endpoint. This flaw can lead to unauthorized actions being performed on behalf of authenticated users, potentially compromising the security of the system and its data.
