EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-11-04T19:09:11

Updated: 2024-08-04T14:22:25.470Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-21139

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-11-04T20:15:07.707

Modified: 2021-11-05T19:05:26.003

Link: CVE-2020-21139

cve-icon Redhat

No data.