Limny CMS version 2.0 suffers from a cross site request forgery vulnerability that allows for a malicious attacker to have an account's password and email address changed. Proof of concept code included.
e3a131335c3eeabc5295e68559c1590bb62ccc68b79ebc84ae7e435c41e4246a