PT-2020-14877 · Hoosk · Hoosk Codeigniter Cms

Havok89

·

Published

2020-08-28

·

Updated

2020-09-02

·

CVE-2020-16610

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hoosk Codeigniter CMS versions prior to 1.7.2
Description The issue allows an attacker to induce an authenticated admin user to a malicious web page, resulting in unintended deletion of any accounts. This occurs due to a Cross Site Request Forgery (CSRF) issue.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16610

Affected Products

Hoosk Codeigniter Cms