Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fatmo666

#52150of 53,624
4.3Total CVSS
Vulnerabilities · 1
PT-2021-17734
4.3
2021-08-25
Popojicms · Popojicms · CVE-2021-28070
Name of the Vulnerable Software and Affected Versions: PopojiCMS version 2.0.1 Description: A Cross Site Request Forgery (CSRF) issue exists, which can be exploited through the `/po-admin/route.php?mod=user&act=multidelete` API endpoint. This allows for potentially unauthorized actions on user accounts. Recommendations: For PopojiCMS version 2.0.1, consider implementing proper CSRF token validation to prevent unauthorized requests to the `/po-admin/route.php?mod=user&act=multidelete` endpoint. As a temporary workaround, restrict access to this endpoint until a proper fix is applied.