Victoralagwu · Cmssite · CVE-2019-25682
**Name of the Vulnerable Software and Affected Versions**
CMSsite version 1.0
**Description**
Cross-site request forgery allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Authenticated administrators can be tricked into visiting pages that submit POST requests to the 'users.php' endpoint using parameters such as `source=add user`, `source=edit user`, or `del=1` to create, modify, or delete administrator accounts.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.