CVE deatail
[Suggested description]
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
[Vulnerability Type]
Cross Site Request Forgery (CSRF)
[Vendor of Product]
https://github.com/Thecosy/IceCMS
[Affected Product Code Base]
IceCMS - v2.0.1
[Affected Component]
After the administrator open the following page and click the the Submit request, cause the CSRF vulnerability.(exp : https://github.com/Thecosy/IceCMS/issues/17)
[Root cause]
The request header does not have csrftoken added.