CVE-2019-16721: CSRF
Published Sep 23, 2019
·Updated
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
Affected Software
1 affected component
5none Nonecms=1.3.0
Event History
Sep 23, 2019
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for NoneCMS v1.3 CSRF?
The vulnerability ID for NoneCMS v1.3 CSRF is CVE-2019-16721.
2
What is the severity of CVE-2019-16721?
The severity of CVE-2019-16721 is medium with a severity value of 6.5.
3
Which software versions are affected by NoneCMS v1.3 CSRF vulnerability?
The vulnerability affects NoneCMS v1.3.0.
4
How does the NoneCMS v1.3 CSRF vulnerability work?
The vulnerability allows attackers to perform CSRF attacks by exploiting the public/index.php/admin/admin/dele.html endpoint to delete the admin user.
5
Is there a fix available for the NoneCMS v1.3 CSRF vulnerability?
Currently, there is no known fix for the NoneCMS v1.3 CSRF vulnerability. It is recommended to update to a newer version of the software if available or to implement additional mitigations.