2019-09-23 13:35:44
mitre
PUBLISHED
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.