First published: Wed Oct 06 2021(Updated: )
A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WHMCS | =1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-21658.
The severity of CVE-2020-21658 is medium with a severity value of 6.5.
The affected software of CVE-2020-21658 is WDJA CMS v1.5.2.
CVE-2020-21658 allows attackers to arbitrarily add administrator accounts via a crafted URL in WDJA CMS v1.5.2.
At the time of writing, there is no known fix available for CVE-2020-21658. It is recommended to update to a newer version of the software if available or apply any patches or mitigation measures provided by the vendor.