source: https://www.securityfocus.com/bid/67604/info User Cake is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests. An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks. User Cake 2.0.2 is vulnerable; prior versions may also be affected.

userCake CSRF Proof of concept

Prerequisite: Make sure the user is logged in to the forum before submitting

Enter CSRFTest user account password to continue... Username: CSRFTest Password: