Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/43462/ | exploit vdb entry third party advisory |
https://open.vanillaforums.com/discussion/28337/vanilla-2-1-5-released-and-2-0-18-14 | issue tracking release notes |