Cross Site Request Forgery Vulnerability in FUEL-CMS by Daylight Studio
CVE-2021-36570
8.8HIGH
What is CVE-2021-36570?
The Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 enables remote attackers to exploit the system by manipulating POST requests to the /permissions/delete/2 endpoint, allowing unauthorized execution of arbitrary code. This can lead to significant security breaches, making it crucial for users to apply necessary updates and patches to secure their applications.
