2019-07-07 14:34:45
mitre
PUBLISHED
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.