Arbitrary forum topic close with GET CSRF.
Low
E
ExpressionEngine
Submitted None
Team Summary
Official summary from ExpressionEngine
A vulnerability was identified and fixed that could have allowed attackers to open or close forum threads by exploiting the lack of CSRF protection.
Actions:
Reported by
d0bby
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)