CVE-2020-20593: CSRF
Published Dec 22, 2021
·Updated
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
Affected Software
1 affected component
Rockoa RockOA=1.9.8
Event History
Dec 22, 2021
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20593?
CVE-2020-20593 is classified as a medium severity vulnerability due to its ability to allow unauthorized account creation.
2
How do I fix CVE-2020-20593?
To mitigate CVE-2020-20593, upgrade Rockoa to a version that addresses this CSRF vulnerability.
3
Who is affected by CVE-2020-20593?
Users of Rockoa version 1.9.8 are impacted by CVE-2020-20593.
4
What kind of vulnerability is CVE-2020-20593?
CVE-2020-20593 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2020-20593 lead to unauthorized access?
Yes, CVE-2020-20593 allows an authenticated attacker to create an administrator account, leading to unauthorized access.