BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-04T15:03:51

Updated: 2024-08-04T17:23:09.125Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2020-36140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-04T16:15:08.150

Modified: 2024-02-14T01:17:43.863

Link: CVE-2020-36140

cve-icon Redhat

No data.