packetstormsecurity.com
http://packetstormsecurity.com/files/159237/BlackCat-CMS-1.3.6-Cross-Site-Request-Forgery.html CVE-2020-25453
HIGH
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
Record summary
CVE-2020-25453 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBlackCat CMS 1.3.6 - Cross-Site Request ForgeryExploitDB exploitby NothNot analyzed1 file
References
3github.com
https://github.com/BlackCatDevelopment/BlackCatCMS/issues/389 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-25453