CVE-2017-1000432

HIGH

Vanilla Forums < 2.1.5 - Cross-Site Request Forgery Leading to Topic and Comment Deletion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-1000432. PoCs published by Anand Meyyappan.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Vanilla Forums below version 2.1.5, allowing any registered user to delete topics and comments without admin access. The PoC is a simple HTML form that submits a POST request to dismiss an announcement.

Description

Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

Exploits (1)

exploitdb WORKING POC VERIFIED
by Anand Meyyappan · htmlwebappsphp
https://www.exploit-db.com/exploits/43462

This exploit demonstrates a CSRF vulnerability in Vanilla Forums below version 2.1.5, allowing any registered user to delete topics and comments without admin access. The PoC is a simple HTML form that submits a POST request to dismiss an announcement.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Vanilla Forums < 2.1.5
Auth required
Prerequisites: Victim must be logged into a vulnerable Vanilla Forums instance · Attacker must know the target discussion ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43462/

Scores

CVSS v3 8.0
EPSS 0.0024
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
vanillaforums/vanilla_forums < 2.1.5
Published Jan 02, 2018
Tracked Since Feb 18, 2026