First published: Thu Sep 10 2020(Updated: )
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-24739.
CVE-2020-24739 has a severity rating of 6.5 (medium).
The CSRF vulnerability was found in iCMS v7.0.0.
If the CSRF_TOKEN is missing, an attacker can still delete all administrators except the initial one.
Currently, there is no information available regarding a fix for the CSRF vulnerability in iCMS v7.0.0.