Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component “/admin/profile/save_profile”.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18694
Reference (s):
- https://github.com/ignitedcms/ignitedcms/issues/5

