my little forum 2.4.12 allows CSRF for deletion of users.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://owendarlene.com/csrf-my-little-forum/ | third party advisory url repurposed |