CVE-2021-36570: CSRF
Published Feb 3, 2023
·Updated
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.13
Remediation
Patch Available
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-36570?
CVE-2021-36570 is a Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 that allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
2
How severe is CVE-2021-36570?
CVE-2021-36570 has a severity score of 8.8, which is considered high.
3
What software versions are affected by CVE-2021-36570?
CVE-2021-36570 affects FUEL-CMS version 1.4.13.
4
How can the Cross Site Request Forgery vulnerability in FUEL-CMS be fixed?
To fix the Cross Site Request Forgery vulnerability in FUEL-CMS, update to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2021-36570?
You can find more information about CVE-2021-36570 at the following reference: https://github.com/daylightstudio/FUEL-CMS/issues/579