"value":"Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under\u00a0\"/edytor/index.php?id=7,7,0\" lacks protection mechanisms.\nA user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If the victim is a logged in administrator, this could lead to creation of new accounts and granting of administrative permissions."
"value":"Los sitios web administrados por MegaBIP en versiones anteriores a la 5.15 son vulnerables a Cross-Site Request Forgery (CSRF), ya que el formulario disponible en \"/edytor/index.php?id=7,7,0\" carece de mecanismos de protecci\u00f3n. Se podr\u00eda enga\u00f1ar a un usuario para que visite un sitio web malicioso, que enviar\u00eda una solicitud POST a este endpoint. Si la v\u00edctima es un administrador conectado, esto podr\u00eda dar lugar a la creaci\u00f3n de nuevas cuentas y la concesi\u00f3n de permisos administrativos."