PT-2021-11024 · Easycms · Easycms

Published

2021-02-01

·

Updated

2021-02-06

·

CVE-2020-24271

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: EasyCMS version 1.6
Description: A CSRF issue was found that can add an admin account through the "index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent" API endpoint, then post username and password variables.
Recommendations: For EasyCMS version 1.6, as a temporary workaround, consider disabling the insert functionality in the /admin/rbacuser module until a patch is available. Restrict access to the "index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent" API endpoint to minimize the risk of exploitation. Avoid using the username and password variables in the affected API endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24271

Affected Products

Easycms