PT-2021-10557 · Qibosoft · Qibosoft

Published

2021-12-27

·

Updated

2022-01-07

·

CVE-2020-20945

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Qibosoft version 7
Description: A Cross-Site Request Forgery (CSRF) issue exists in the /admin/index.php?lfj=member&action=editmember endpoint of Qibosoft, allowing attackers to add administrator accounts arbitrarily.
Recommendations: For Qibosoft version 7, as a temporary workaround, consider restricting access to the /admin/index.php?lfj=member&action=editmember endpoint until a patch is available. Avoid using the action and lfj parameters in this endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20945

Affected Products

Qibosoft