packetstormsecurity.com
http://packetstormsecurity.com/files/158455/CMSUno-1.6-Cross-Site-Request-Forgery.html CVE-2020-15600
MEDIUM
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
Record summary
CVE-2020-15600 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)ExploitDB exploitby NothNot analyzed1 file
References
3github.comConfirmation
https://github.com/boiteasite/cmsuno/issues/15 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-15600