Junglewise Threat Intelligence

CVE-2018-25363: Fyffe Twitter-Clone CSRF in tweetdel.php

CVE-2018-25363 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Technologies: Fyffe Twitter-Clone. Vendors: Fyffe.

Executive brief

Twitter-Clone is a PHP-based social media application. A security flaw allows an attacker to trick a logged-in user into unintentionally deleting their own posts. This occurs when a victim visits a malicious website that silently sends a deletion request to the Twitter-Clone application on the user's behalf, potentially leading to data loss and unauthorized content removal.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Twitter-Clone version 1.0 and earlier due to a lack of anti-CSRF tokens in the tweet deletion routine. The vulnerable component, tweetdel.php, processes deletion requests via POST parameters without verifying the intent of the authenticated user. An attacker can exploit this by hosting a malicious HTML page with a hidden form that targets tweetdel.php with a specific tweet ID. When an authenticated user visits the attacker's page, the form is automatically submitted via JavaScript, causing the application to delete the specified post from the user's account. This vulnerability requires the victim to be authenticated and to interact with a malicious link or site.

Affected products

  • Fyffe (PHP-Twitter-Clone) Twitter-Clone 1.0 and earlier

Timeline

  • 2018-08-21: disclosed: Original exploit published on Exploit-DB
  • 2026-05-25: advisory: NVD and VulnCheck published formal advisory details

References

Related threats