An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1jN3gyLTdoOHItanE0bc4AAuav

Moderate EPSS: 0.00164% (0.37827 Percentile) EPSS:

Kirby CMS 2.5.12 Cross-site Request Forgery

Affected Packages Affected Versions Fixed Versions
packagist:getkirby/cms <= 2.5.12 No known fixed version
223 Dependent packages
378 Dependent repositories
452,886 Downloads total

Affected Version Ranges

All affected versions

An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.

References: