CVE-2020-36140

Publication date

2021-06-04 15:03:51

Family

mitre

State

PUBLISHED

Description

BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via mode=settings&page=editor, as demonstrated by use of mode=settings&page=editor to change any file content (Locally/Remotely).