Vulnerability Description
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easycms | Easycms | 1.6 |
Related Weaknesses (CWE)
References
- https://github.com/users/yohoho221/projects/1ExploitThird Party Advisory
- https://github.com/users/yohoho221/projects/1ExploitThird Party Advisory
FAQ
What is CVE-2020-24271?
CVE-2020-24271 is a vulnerability with a CVSS score of 8.8 (HIGH). A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&passwor...
How severe is CVE-2020-24271?
CVE-2020-24271 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24271?
Check the references section above for vendor advisories and patch information. Affected products include: Easycms Easycms.