A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://anchorcms.com/ | product vendor advisory |
https://anchorcms.com/ | product vendor advisory |
https://twitter.com/NinadMishra5/status/1350077938176151558 | third party advisory exploit |
http://packetstormsecurity.com/files/161048/Anchor-CMS-0.12.7-Cross-Site-Request-Forgery.html | third party advisory vdb entry exploit |