Vulnerability Description
An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jyuu | Jymusic | 2.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/dtorp06/jymusic/issues/1ExploitIssue Tracking
- https://github.com/dtorp06/jymusic/issues/1ExploitIssue Tracking
FAQ
What is CVE-2020-18416?
CVE-2020-18416 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information...
How severe is CVE-2020-18416?
CVE-2020-18416 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-18416?
Check the references section above for vendor advisories and patch information. Affected products include: Jyuu Jymusic.