CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6918.json"