First published: Fri Feb 03 2023(Updated: )
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TheDayLightStudio Fuel CMS | =1.4.13 | |
=1.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36569 is a Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13.
CVE-2021-36569 allows remote attackers to run arbitrary code by exploiting a Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13.
CVE-2021-36569 has a severity level of 8.8, which is considered high.
To fix CVE-2021-36569, it is recommended to update to a version of FUEL-CMS that is not affected by the vulnerability.
You can find more information about CVE-2021-36569 at the following reference link: [https://github.com/daylightstudio/FUEL-CMS/issues/578](https://github.com/daylightstudio/FUEL-CMS/issues/578)