public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7571.json"