PT-2026-30490 · Victoralagwu · Cmssite

Mr Winst0N

·

Publicado

2026-04-05

·

Atualizado

2026-04-05

·

CVE-2019-25682

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add user, source=edit user, or del=1 to create, modify, or delete admin accounts.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25682

Produtos afetados

Cmssite