CVE-2021-36569: CSRF
Published Feb 3, 2023
·Updated
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.13
Remediation
Patch Available
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-36569?
CVE-2021-36569 is a Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13.
2
How does CVE-2021-36569 impact FUEL-CMS?
CVE-2021-36569 allows remote attackers to run arbitrary code by exploiting a Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13.
3
What is the severity of CVE-2021-36569?
CVE-2021-36569 has a severity level of 8.8, which is considered high.
4
How can I fix CVE-2021-36569?
To fix CVE-2021-36569, it is recommended to update to a version of FUEL-CMS that is not affected by the vulnerability.
5
Where can I find more information about CVE-2021-36569?
You can find more information about CVE-2021-36569 at the following reference link: [https://github.com/daylightstudio/FUEL-CMS/issues/578](https://github.com/daylightstudio/FUEL-CMS/issues/578)