An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.
| Software | From | Fixed in |
|---|---|---|
getkirby / kirby
|
2.5.12 | 2.5.12.x |
getkirby / cms
|
- | 2.5.12.x |