PT-2021-10194 · Juqingcms · Juqingcms

CVE-2020-18648

·

Published

2021-06-22

·

Updated

2022-10-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: JuQingCMS version 1.0
Description: The issue allows remote attackers to gain local privileges. It is related to a Cross Site Request Forgery (CSRF) in the component "admin/index.php?c=administrator&a=add".
Recommendations: For JuQingCMS version 1.0, as a temporary workaround, consider disabling access to the "admin/index.php?c=administrator&a=add" endpoint until a patch is available. Restrict access to the administrator component to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18648

Affected Products

Juqingcms