CVE-2020-36065: CSRF
Published May 8, 2023
·Updated
Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/adminsave.
Affected Software
1 affected component
Flycms Project Flycms=1.0
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-36065?
CVE-2020-36065 has a high severity rating due to its ability to allow unauthorized users to create arbitrary administrator accounts.
2
How do I fix CVE-2020-36065?
To fix CVE-2020-36065, update FlyCms to a version that addresses this vulnerability.
3
What kind of attacks can be performed using CVE-2020-36065?
Attackers can exploit CVE-2020-36065 to perform Cross-Site Request Forgery (CSRF) attacks, allowing them to add malicious administrator accounts.
4
Who is affected by CVE-2020-36065?
CVE-2020-36065 affects all users of FlyCms version 1.0.
5
What actions should I take if I am affected by CVE-2020-36065?
If affected by CVE-2020-36065, immediately update your FlyCms installation and review user accounts for any unauthorized additions.