An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14989
Reference (s):
- https://tvrbk.github.io/cve/2021/03/09/brXM.html