CVE-2020-20514: CSRF
Published Sep 24, 2021
·Updated
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
Affected Software
1 affected component
maccms Maccms=10.0
Event History
Sep 24, 2021
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site request forgery (CSRF) vulnerability in Maccms v10?
The vulnerability ID for this CSRF vulnerability in Maccms v10 is CVE-2020-20514.
2
What is the severity rating of CVE-2020-20514?
CVE-2020-20514 has a severity rating of 8.1 (high).
3
How does the vulnerability in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allow attackers to exploit it?
The vulnerability in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
4
What is the Common Weakness Enumeration (CWE) number associated with CVE-2020-20514?
The Common Weakness Enumeration (CWE) number associated with CVE-2020-20514 is CWE-352.
5
Is there any reference or documentation available for CVE-2020-20514?
Yes, you can find more information about CVE-2020-20514 at this link: https://github.com/magicblack/maccms10/issues/76.