CVE-2020-25263

Published
View on NVD ↗
CVSS v3
7.1
HIGH
CVSS v2
5.8
MEDIUM
Affected
1
PROJECT

Description

PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.

Pyro is an experienced and powerful Laravel PHP CMS.
GitHubGitHub
3.18K