In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
{
"versions": [
{
"introduced": "4.0.1"
},
{
"last_affected": "9.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha3"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha4"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha5"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha6"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha7"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha8"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-alpha9"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "4.0.0-rc1"
}
]
}