rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.
razorcms razorcms 3.4.8