Home <= 2.6.6
affected
Description
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
Problem types
CWE-352: Cross-Site Request Forgery (CSRF)
Product status
References
github.com/.../emlog/security/advisories/GHSA-xc26-93qj-rcrw