CVE-2020-36140: CSRF
Published Jun 4, 2021
·Updated
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Jun 4, 2021
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36140.
2
What is the severity of CVE-2020-36140?
The severity of CVE-2020-36140 is medium with a severity value of 6.5.
3
How does CVE-2020-36140 affect BloofoxCMS?
CVE-2020-36140 allows Cross-Site Request Forgery (CSRF) in BloofoxCMS 0.5.2.1 via 'mode=settings&page=editor', allowing unauthorized changes to file content.
4
What is the CWE-ID for CVE-2020-36140?
The CWE-ID for CVE-2020-36140 is 352.
5
Is there a source with more information about CVE-2020-36140?
Yes, you can find more information about CVE-2020-36140 at this URL: https://muteb.io/2020/12/29/BloofoxCMS-Multiple-Vulnerabilities.html