Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/flatpressblog/flatpress/issues/64 | patch exploit third party advisory issue tracking |
https://www.baomatcoban.info/2020/04/funnymini0day-flatpress-11-cross-site.html | broken link url repurposed third party advisory |