WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.wondercms.com/forum/viewtopic.php?f=8&p=1684 | patch vendor advisory |
https://github.com/robiso/wondercms/releases/tag/2.0.3 | patch third party advisory issue tracking |