Cross-Site Request Forgery in Anchor CMS by Butterfly Hack
CVE-2022-25576

4.5MEDIUM

Key Information:

Vendor

Anchorcms

Vendor
CVE Published:
24 March 2022

What is CVE-2022-25576?

Anchor CMS version 0.12.7 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability found within the anchor/routes/posts.php component. Exploiting this flaw can allow malicious actors to delete posts without proper authorization, potentially leading to data loss and disruption. Users are encouraged to review their security practices and update accordingly.

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.