CVE-2016-20053
MEDIUMRedaxo CMS 5.2 Cross-Site Request Forgery via users endpoint
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20053. PoCs published by Amir.ght.
AI-analyzed exploit summary This is a functional CSRF exploit for Redaxo CMS 5.2 that adds an admin user by submitting a crafted form. The PoC includes all necessary hidden fields to create an admin account with predefined credentials.
Description
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields containing admin credentials and account parameters to add new administrator accounts without user consent.
Exploits (1)
This is a functional CSRF exploit for Redaxo CMS 5.2 that adds an admin user by submitting a crafted form. The PoC includes all necessary hidden fields to create an admin account with predefined credentials.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N