CVE-2024-29499
Description
Anchor CMS v0.12.7 is vulnerable to Cross-Site Request Forgery (CSRF) via the /anchor/admin/users/delete/2 endpoint, allowing an attacker to delete users without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Anchor CMS v0.12.7 is vulnerable to Cross-Site Request Forgery (CSRF) via the /anchor/admin/users/delete/2 endpoint, allowing an attacker to delete users without authentication.
Vulnerability
CVE-2024-29499 describes a Cross-Site Request Forgery (CSRF) vulnerability in Anchor CMS v0.12.7, specifically in the /anchor/admin/users/delete/2 endpoint. The official description states that the application was discovered to contain this flaw [1]. The project is no longer maintained and is not considered production-ready [2], meaning no patches will be provided.
Exploitation
A proof-of-concept (PoC) demonstrates that an attacker can craft a form that automatically submits a request to the vulnerable endpoint when a logged-in admin visits a malicious page [3]. The PoC uses a simple HTML form with action="http://127.0.0.1/anchor/admin/users/delete/2" to trigger a user deletion. The exploitation requires the victim to be authenticated and to interact with the attacker-controlled page (e.g., through a link or embedded content). No other authentication or privileges are needed; the session of the victim is abused.
Impact
Successful exploitation allows an attacker to force the deletion of a specific user (ID 2) without the victim's consent. This could lead to loss of administrative access or disruption of the site's functionality. Since the application is end-of-life and unmaintained [2], any installation running v0.12.7 remains vulnerable.
Mitigation
No patch is available, and the vendor recommends migrating to alternative platforms [2]. Users should restrict access to the admin panel via network controls, implement additional CSRF protections (such as custom tokens or same-site cookies), or consider decommissioning the application.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
anchorcms/anchor-cmsPackagist | <= 0.12.7 | — |
Affected products
2- Anchor CMS/Anchor CMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-4xw8-9fj7-j58jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-29499ghsaADVISORY
- github.com/daddywolf/cms/blob/main/1.mdghsaWEB
News mentions
0No linked articles in our index yet.