A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/sansanyun/mipcms5/issues/4 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-09-09T17:44:40
Updated: 2024-08-04T14:08:30.808Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-19264
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-09-09T18:15:08.400
Modified: 2021-09-20T16:18:40.717
Link: CVE-2020-19264
Redhat
No data.