An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
- https://github.com/chshcms/cscms/issues/4
No PoCs found on GitHub currently.