CVE-2016-20054
MEDIUMNodcms Cross Site Request Forgery via admin endpoints
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20054. PoCs published by Amir.ght.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in nodcms, allowing an attacker to create a new admin user or inject XSS payloads via crafted POST requests. The PoC includes functional HTML forms targeting the vulnerable endpoints.
Description
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to create users or modify application settings without explicit consent.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in nodcms, allowing an attacker to create a new admin user or inject XSS payloads via crafted POST requests. The PoC includes functional HTML forms targeting the vulnerable endpoints.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N