CVE deatail

[Suggested description]
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).


[Vulnerability Type]
Cross Site Request Forgery (CSRF)


[Vendor of Product]
https://github.com/Thecosy/IceCMS


[Affected Product Code Base]
IceCMS - v2.0.1


[Affected Component]
After the administrator open the following page and click the the Submit request, cause the CSRF vulnerability.(exp : https://github.com/Thecosy/IceCMS/issues/17)


[Root cause]
The request header does not have csrftoken added.