EGSA-2026-05: Cross-site request forgery of the clean-up links of the back end

The two links on the overview page of the back end which remove file entries without an event and carts older than 30 days from the database did not carry the form token. A prepared page on another web site could therefore trigger them in the name of a logged in administrator. Orders are not affected.

  • Needed: no account. The victim is logged in to the back end with the permission Manage of Event Gallery and opens a prepared page.
  • Affected: all versions before 6.5.0 except 4.3.3.
  • Fixed in: 6.5.0 and 4.3.3. Both links need the form token and the permission Manage.
  • Severity: CVSS 4.0 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352.
  • CVE: CVE-2026-100749.
All prices include VAT. The gross price will vary depending on the selected shipping country.