Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user sessions.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fyffe
Fyffe php-twitter-clone |
|
| Vendors & Products |
Fyffe
Fyffe php-twitter-clone |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user sessions. | |
| Title | Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-25T14:15:10.194Z
Updated: 2026-05-26T13:18:54.724Z
Reserved: 2026-05-24T13:31:38.682Z
Link: CVE-2018-25363
Updated: 2026-05-26T13:18:50.798Z
Status : Deferred
Published: 2026-05-25T15:16:18.920
Modified: 2026-05-26T19:47:48.987
Link: CVE-2018-25363
No data.
ReportizFlow