PT-2020-15834 · Icms · Icms

Published

2020-09-10

·

Updated

2020-09-16

·

CVE-2020-24739

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions iCMS version 7.0.0
Description A CSRF issue was discovered in the background deletion administrator account. This occurs when the CSRF TOKEN is missing, yet requests can still be made normally, resulting in the deletion of all administrators except the initial one.
Recommendations For iCMS version 7.0.0, ensure that the CSRF TOKEN is properly validated to prevent unauthorized requests. As a temporary workaround, consider implementing additional validation checks for the CSRF TOKEN to mitigate the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24739

Affected Products

Icms