First published: Fri Oct 09 2020(Updated: )
A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Garfield Petshop Project Garfield Petshop | <=2020-10-01 | |
<=2020-10-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26522 is a cross-site request forgery (CSRF) vulnerability in Garfield Petshop that allows remote attackers to hijack the authentication of administrators.
CVE-2020-26522 allows remote attackers to create new administrative accounts using the hijacked authentication of administrators.
The severity of CVE-2020-26522 is high with a CVSS score of 8.8.
To fix CVE-2020-26522, it is recommended to apply the latest patch or update provided by Garfield Petshop Project.
Yes, you can find more information about CVE-2020-26522 at the following references: http://packetstormsecurity.com/files/159520/Garfield-Petshop-2020-10-01-Cross-Site-Request-Forgery.html, http://rysec.io/adv/Petshop_AddAdmin_Exploit.txt, https://demo.detapos.co.id/petshop/