A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users.
- https://github.com/magicblack/maccms10/issues/76
No PoCs found on GitHub currently.