PT-2021-11926 · Unknown · Bloofoxcms

Published

2021-06-04

·

Updated

2024-02-14

·

CVE-2020-36140

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: BloofoxCMS version 0.5.2.1
Description: The issue allows for Cross-Site Request Forgery (CSRF) via the "mode=settings&page=editor" endpoint. This can be exploited to change any file content, both locally and remotely, by utilizing the "mode=settings&page=editor" endpoint.
Recommendations: For BloofoxCMS version 0.5.2.1, as a temporary workaround, consider restricting access to the "mode=settings&page=editor" endpoint until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-36140

Affected Products

Bloofoxcms