Vulnerability Description
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ponzu-Cms | Ponzu | 0.11.0 |
Related Weaknesses (CWE)
References
- https://github.com/ponzu-cms/ponzu/issues/352ExploitIssue TrackingThird Party Advisory
- https://github.com/ponzu-cms/ponzu/issues/352ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-24130?
CVE-2020-24130 is a vulnerability with a CVSS score of 8.1 (HIGH). A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator account...
How severe is CVE-2020-24130?
CVE-2020-24130 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24130?
Check the references section above for vendor advisories and patch information. Affected products include: Ponzu-Cms Ponzu.